Skip to main content

Pyload ng: pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host

0
Medium
Published: 10/09/2026 (10/09/2026, 17:09:03 UTC)
Source: GCVE Database
Product: pyload-ng

Description

pyLoad-ng's WindowsPhoneNotify addon allows an authenticated user with non-admin SETTINGS permission to configure the addon to send HTTP POST requests to arbitrary internal hosts. This occurs because the addon uses Python's http.client.HTTPConnection without outbound address validation, bypassing pyLoad's usual SSRF protections. The attacker can control the destination host, port, request path, and part of the request body. This can lead to blind SSRF attacks enabling internal service probing and potential state changes on internal HTTP endpoints. The vulnerability affects pyLoad-ng versions up to 0.5.0b3.dev101 and has a CVSS score of 6.4 (medium severity).

CVSS v3.1

Score 6.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Affected software

PyPIghsa
pyload-ng
Affected versions
<=0.5.0b3.dev101

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 22:53:42 UTC

Technical Analysis

The WindowsPhoneNotify addon in pyLoad-ng uses the http.client.HTTPConnection class to send HTTP POST notifications to a host specified by the plugin's pushurl configuration. A user with the non-admin SETTINGS permission can set pushurl, pushid, and enable the addon via the web API because these options are not restricted to admin users. The addon activates immediately without restart, and any completed download triggers a POST request to the configured host and path. This request bypasses pyLoad's outbound SSRF protections, which only apply to pycurl-based connections, allowing blind SSRF attacks to internal network addresses including loopback, RFC 1918 ranges, and cloud metadata endpoints. The vulnerability arises from insufficient authorization on configuration options and lack of address validation in the HTTP client used by the addon.

Potential Impact

An authenticated user with SETTINGS permission can cause the pyLoad server to send blind HTTP POST requests to arbitrary internal hosts and ports that the user cannot access directly. This enables internal network reconnaissance, probing of hosts and ports, and interaction with internal HTTP services that respond to POST requests. Confidentiality and integrity impacts are limited to what can be inferred or triggered via these blind requests; no direct availability impact has been demonstrated.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict SETTINGS permission to trusted users only and monitor configuration changes to the WindowsPhoneNotify addon. Consider disabling the WindowsPhoneNotify addon if not required. The vendor advisory does not indicate any official fix or temporary workaround at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-p3pr-8f3m-4qp8
Osv Schema Version
1.4.0
Ecosystems
["PyPI"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac96e612cdf04f65689a8fe

Added to database: 10/09/2026, 22:44:49 UTC

Last enriched: 10/09/2026, 22:53:42 UTC

Last updated: 10/09/2026, 22:53:42 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses