Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2025-53890: pyLoad Download Manager CAPTCHA Hack Allows Remote Code Execution
GHSA-8w3f-4r8f-pf53
CVE-2025-53890
PYSEC-2026-496
Summary
An attacker can execute code on your computer and gain access to your pyLoad account without needing a password. This can lead to stolen passwords, hijacked sessions, and complete control of your computer. Update to the latest version of pyLoad, at least 0.5.0b3.dev89, to fix this issue.
What to do
- Update pyload-ng to version 0.20.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | – | pyload-ng |
< 0.20 Fix: upgrade to 0.20
|
Original title
pyLoad vulnerable to XSS through insecure CAPTCHA
Original description
#### Summary
An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows **unauthenticated remote attackers** to execute **arbitrary code** in the client browser and potentially the backend server. Exploitation requires no user interaction or authentication and can result in session hijacking, credential theft, and full system rce.
#### Details
The vulnerable code resides in
```javascript
function onCaptchaResult(result) {
eval(result); // Direct execution of attacker-controlled input
}
```
* The `onCaptchaResult()` function directly passes CAPTCHA results (sent from the user) into `eval()`
* No sanitization or validation is performed on this input
* A malicious CAPTCHA result can include JavaScript such as `fetch()` or `child_process.exec()` in environments using NodeJS
* Attackers can fully hijack sessions and pivot to remote code execution on the server if the environment allows it
### Reproduction Methods
1. **Official Source Installation**:
```bash
git clone https://github.com/pyload/pyload
cd pyload
git checkout 0.4.20
python -m pip install -e .
pyload --userdir=/tmp/pyload
```
2. **Virtual Environment**:
```bash
python -m venv pyload-env
source pyload-env/bin/activate
pip install pyload==0.4.20
pyload
```
## CAPTCHA Endpoint Verification
**Technical Clarification**:
1. The vulnerable endpoint is actually:
```
/interactive/captcha
```
2. Complete PoC Request:
```http
POST /interactive/captcha HTTP/1.1
Host: localhost:8000
Content-Type: application/x-www-form-urlencoded
cid=123&response=1%3Balert(document.cookie)
```
3. Curl Command Correction:
```bash
curl -X POST "http://localhost:8000/interactive/captcha" \
-d "cid=123&response=1%3Balert(document.cookie)"
```
1. **Vulnerable Code Location**:
The eval() vulnerability is confirmed in:
```
src/pyload/webui/app/static/js/captcha-interactive.user.js
```
### **Resources**
1. https://github.com/pyload/pyload/commit/909e5c97885237530d1264cfceb5555870eb9546
2. [OWASP: Avoid `eval()`](https://cheatsheetseries.owasp.org/cheatsheets/JavaScript_Security_Cheat_Sheet.html#eval)
3. [#4586](https://github.com/pyload/pyload/pull/4586)
An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows **unauthenticated remote attackers** to execute **arbitrary code** in the client browser and potentially the backend server. Exploitation requires no user interaction or authentication and can result in session hijacking, credential theft, and full system rce.
#### Details
The vulnerable code resides in
```javascript
function onCaptchaResult(result) {
eval(result); // Direct execution of attacker-controlled input
}
```
* The `onCaptchaResult()` function directly passes CAPTCHA results (sent from the user) into `eval()`
* No sanitization or validation is performed on this input
* A malicious CAPTCHA result can include JavaScript such as `fetch()` or `child_process.exec()` in environments using NodeJS
* Attackers can fully hijack sessions and pivot to remote code execution on the server if the environment allows it
### Reproduction Methods
1. **Official Source Installation**:
```bash
git clone https://github.com/pyload/pyload
cd pyload
git checkout 0.4.20
python -m pip install -e .
pyload --userdir=/tmp/pyload
```
2. **Virtual Environment**:
```bash
python -m venv pyload-env
source pyload-env/bin/activate
pip install pyload==0.4.20
pyload
```
## CAPTCHA Endpoint Verification
**Technical Clarification**:
1. The vulnerable endpoint is actually:
```
/interactive/captcha
```
2. Complete PoC Request:
```http
POST /interactive/captcha HTTP/1.1
Host: localhost:8000
Content-Type: application/x-www-form-urlencoded
cid=123&response=1%3Balert(document.cookie)
```
3. Curl Command Correction:
```bash
curl -X POST "http://localhost:8000/interactive/captcha" \
-d "cid=123&response=1%3Balert(document.cookie)"
```
1. **Vulnerable Code Location**:
The eval() vulnerability is confirmed in:
```
src/pyload/webui/app/static/js/captcha-interactive.user.js
```
### **Resources**
1. https://github.com/pyload/pyload/commit/909e5c97885237530d1264cfceb5555870eb9546
2. [OWASP: Avoid `eval()`](https://cheatsheetseries.owasp.org/cheatsheets/JavaScript_Security_Cheat_Sheet.html#eval)
3. [#4586](https://github.com/pyload/pyload/pull/4586)
ghsa CVSS3.1
9.8
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
CWE-94
Code Injection
- https://github.com/pyload/pyload/security/advisories/GHSA-8w3f-4r8f-pf53
- https://nvd.nist.gov/vuln/detail/CVE-2025-53890
- https://github.com/pyload/pyload/pull/4586
- https://github.com/advisories/GHSA-8w3f-4r8f-pf53
- https://github.com/pyload/pyload/commit/909e5c97885237530d1264cfceb5555870eb9546
- https://github.com/pyload/pyload Product
- https://pypi.org/project/pyload-ng Product
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 6 Mar 2026