{"id":"CVE-2025-53890","aliases":["GHSA-8w3f-4r8f-pf53","PYSEC-2026-496"],"title":"pyLoad vulnerable to XSS through insecure CAPTCHA ","summary":"pyLoad vulnerable to XSS through insecure CAPTCHA ","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"pyload-ng","product":"pyload-ng","ecosystem":"pip","affected":["pyload-ng < 0.20"],"patched":["pyload-ng 0.20"],"published":"2025-07-15","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:25.994941188Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8w3f-4r8f-pf53","references":[{"url":"https://github.com/pyload/pyload/security/advisories/GHSA-8w3f-4r8f-pf53"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53890"},{"url":"https://github.com/pyload/pyload/pull/4586"},{"url":"https://github.com/pyload/pyload/commit/909e5c97885237530d1264cfceb5555870eb9546"},{"url":"https://github.com/pyload/pyload"},{"url":"https://pypi.org/project/pyload-ng"},{"url":"https://github.com/advisories/GHSA-8w3f-4r8f-pf53"}],"tags":["osv","pip"],"epss":0.01162,"epssPercentile":0.65812,"ingestedAt":"2026-07-09T18:56:35.413Z","slug":"CVE-2025-53890","body":"## Overview\n\n#### Summary\nAn unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows **unauthenticated remote attackers** to execute **arbitrary code** in the client browser and potentially the backend server. Exploitation requires no user interaction or authentication and can result in session hijacking, credential theft, and full system rce.\n\n\n\n#### Details\nThe vulnerable code resides in \n```javascript\nfunction onCaptchaResult(result) {\n    eval(result); // Direct execution of attacker-controlled input\n}\n```\n\n* The `onCaptchaResult()` function directly passes CAPTCHA results (sent from the user) into `eval()`\n* No sanitization or validation is performed on this input\n* A malicious CAPTCHA result can include JavaScript such as `fetch()` or `child_process.exec()` in environments using NodeJS\n* Attackers can fully hijack sessions and pivot to remote code execution on the server if the environment allows it\n\n\n\n### Reproduction Methods\n1. **Official Source Installation**:\n```bash\ngit clone https://github.com/pyload/pyload\ncd pyload\ngit checkout 0.4.20\npython -m pip install -e .\npyload --userdir=/tmp/pyload\n```\n\n2. **Virtual Environment**:\n```bash\npython -m venv pyload-env\nsource pyload-env/bin/activate\npip install pyload==0.4.20\npyload\n```\n\n## CAPTCHA Endpoint Verification\n\n\n**Technical Clarification**:  \n1. The vulnerable endpoint is actually:\n   ```\n   /interactive/captcha\n   ```\n\n2. Complete PoC Request:\n```http\nPOST /interactive/captcha HTTP/1.1\nHost: localhost:8000\nContent-Type: application/x-www-form-urlencoded\n\ncid=123&response=1%3Balert(document.cookie)\n```\n\n3. Curl Command Correction:\n```bash\ncurl -X POST \"http://localhost:8000/interactive/captcha\" \\\n  -d \"cid=123&response=1%3Balert(document.cookie)\"\n```\n\n\n1. **Vulnerable Code Location**:  \n   The eval() vulnerability is confirmed in:\n   ```\n   src/pyload/webui/app/static/js/captcha-interactive.user.js\n   ```\n\n\n\n### **Resources**\n\n1. https://github.com/pyload/pyload/commit/909e5c97885237530d1264cfceb5555870eb9546\n2. [OWASP: Avoid `eval()`](https://cheatsheetseries.owasp.org/cheatsheets/JavaScript_Security_Cheat_Sheet.html#eval)\n3. [#4586](https://github.com/pyload/pyload/pull/4586)\n\n## Affected packages\n\n- `pyload-ng < 0.20`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pyload-ng 0.20`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}