PT-2026-36322 · Alexta69 · Metube
Aliaz
·
Published
2026-05-01
·
Updated
2026-05-01
·
CVE-2026-7581
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
alexta69 MeTube versions prior to 2026.04.10
Description
A permissive cross-domain policy exists in the CORS Policy component, specifically within the
on prepare() function of the app/main.py file. This allows untrusted domains to bypass restrictions, enabling remote exploitation of cross-domain controls.Recommendations
Upgrade to version 2026.04.10.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Metube