<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:01:43.561226+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-41133</id>
    <title>CVE-2026-41133 — pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)</title>
    <updated>2026-10-02T22:01:43.562885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> pyload</p>
<p>pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the database. As a result, an already logged-in user can keep old (revoked) privileges until logout/session expiry, enabling continued privileged actions. This is a core authorization/session-consistency issue and is not resolved by toggling an optional security feature. Commit e95804fb0d06cbb07d2ba380fc494d9ff89b68c1 contains a fix for the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-41133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-66hx-chf7-3332</id>
    <title>GHSA-66hx-chf7-3332 — pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)</title>
    <updated>2026-10-02T22:01:43.562940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyload-ng</p>
<p>### Summary
pyLoad caches `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the database.</p>
<p>As a result, an already logged-in user can keep old (revoked) privileges until logout/session expiry, enabling continued privileged actions.</p>
<p>This is a core authorization/session-consistency issue and is not resolved by toggling an optional security feature.</p>
<p>### Details
The WebUI auth flow stores authorization state in session:</p>
<p>- `src/pyload/webui/app/helpers.py:187-200`
  - `set_session(...)` writes:
    - `"role": user_info["role"]`
    - `"perms": user_info["permission"]`</p>
<p>Authorization checks later trust cached session values:</p>
<p>- `src/pyload/webui/app/helpers.py:134-151`
  - `parse_permissions(...)` reads `session.get("role")` / `session.get("perms")`
- `src/pyload/webui/app/helpers.py:225-230`
  - `is_authenticated(...)` only verifies `authenticated` and `api.user_exists(user)` (existence), not fresh role/permission
- `src/pyload/webui/app/helpers.py:267-275`
  - `login_required(...)` uses `parse_permissions(s)` for allow/deny decisions
- `src/pyload/webui/app/helpers.py:356-365`
  - API session auth path also trusts `s["role"]` and `s["perms"]`</p>
<p>Role/permission updates are written to DB but active sessions are not invalidated/refreshed:</p>
<p>- `src/pyload/webui/app/blueprints/json_blueprint.py:389-434`
  - `update_users(...)` calls `api.set_user_permission(...)` a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-66hx-chf7-3332"/>
  </entry>
</feed>
