PT-2026-36322 · Alexta69 · Metube

Aliaz

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7581

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions alexta69 MeTube versions prior to 2026.04.10
Description A permissive cross-domain policy exists in the CORS Policy component, specifically within the on prepare() function of the app/main.py file. This allows untrusted domains to bypass restrictions, enabling remote exploitation of cross-domain controls.
Recommendations Upgrade to version 2026.04.10.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-7581

Affected Products

Metube