Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

GHSA-JQ7H-WRVP-3RGX: GHSA-JQ7H-WRVP-3RGX: Insufficient Session Invalidation in pyLoad Core REST API

GHSA-JQ7H-WRVP-3RGX: Insufficient Session Invalidation in pyLoad Core REST API Vulnerability ID: GHSA-JQ7H-WRVP-3RGX CVSS Score: 7.5 Published: 2026-10-09 An insufficient session invalidation vulnerability exists in

GHSA-JQ7H-WRVP-3RGX: Insufficient Session Invalidation in pyLoad Core REST API

Vulnerability ID: GHSA-JQ7H-WRVP-3RGX
CVSS Score: 7.5
Published: 2026-10-09

An insufficient session invalidation vulnerability exists in pyLoad (pyload-ng) versions 0.5.0b3.dev98 through 0.5.0b3.dev101. When administrative actions like privilege revocation or password changes are executed via the public REST API, active user sessions on disk are not updated or invalidated. Consequently, affected sessions remain fully authenticated with stale permissions for up to 31 days.

TL;DR

Administrative changes via the pyLoad REST API (such as password changes or permission downgrades) do not invalidate active filesystem-based Flask sessions. Affected users retain their original high-privilege permissions for the entire session lifetime (up to 31 days) unless sessions are manually purged.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-613
  • Attack Vector: Network
  • CVSS Score: 7.5
  • Exploit Status: Proof of Concept available
  • Impact: Privilege Escalation / Persistent Session Hijack

Affected Systems

  • pyLoad (pyload-ng) Web UI & REST API
  • pyload-ng: >= 0.5.0b3.dev98, <= 0.5.0b3.dev101 (Fixed in: Commit 3e726ba271a6b1015e3a0ea6dc7e46a8f71a62ad)

Code Analysis

Commit: 3e726ba

Fix session invalidation when administrative or password actions are executed through the core API.

Mitigation Strategies

  • Deploy the unified code patch to register Web UI session invalidators into the core API.
  • Reduce default session lifetimes in configurations.
  • Manually clear server session files if API password resets or permission downgrades are performed.

Remediation Steps:

  1. Apply the patch from commit 3e726ba271a6b1015e3a0ea6dc7e46a8f71a62ad.
  2. Locate the default.cfg file and set the session_lifetime parameter to a lower, safer value like 60 minutes.
  3. Restart the pyLoad process and purge the filesystem directory configured under SESSION_FILE_DIR.

References

Read the full report for GHSA-JQ7H-WRVP-3RGX on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.