PT-2026-28518 · Mytube · Mytube
Daniel-Grunbergerca
·
Published
2026-03-27
·
Updated
2026-03-27
·
CVE-2026-33735
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyTube versions prior to 1.8.69
Description
MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.8.69, an authorization bypass exists in the
/api/settings/import-database API endpoint. This bypass allows attackers with low-privilege credentials to upload and replace the application's SQLite database, resulting in a full compromise of the application. The bypass is also relevant for other POST routes.Recommendations
Versions prior to 1.8.69 should be updated to version 1.8.69 or later.
Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mytube