PT-2026-36322 · Alexta69 · Metube

Aliaz

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7581

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions alexta69 MeTube versions prior to 2026.04.10
Description A permissive cross-domain policy exists in the CORS Policy component, specifically within the on prepare() function of the app/main.py file. This allows untrusted domains to bypass cross-domain restrictions, enabling remote exploitation.
Recommendations Upgrade to version 2026.04.10.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7581

Affected Products

Metube