Impact
MyTube is a self-hosted downloader and media player that, before version 1.8.71, allowed an unauthenticated attacker to register any desired passkey through exposed endpoints. Once registered, the passkey could be used to authenticate and automatically receive an administrator token, granting full control of the application. This weakness corresponds to CWE‑284 (Improper Access Control) and carries a CVSS score of 8.9, indicating significant risk if exploited.
Affected Systems
The flaw impacts the FrankLioxygen MyTube application, specifically all releases prior to 1.8.71. Users running version 1.8.70 or earlier are vulnerable; upgrading to 1.8.71 or later removes the attack surface.
Risk and Exploitability
With the attack path available over publicly reachable HTTP endpoints and no authentication required, the vulnerability is easily exploitable over the network. The EPSS score of less than 1% suggests a low current exploitation frequency, but the lack of prior credential requirement and the full administrative takeover make it a high severity risk. The vulnerability is not listed in the CISA KEV catalog at this time, yet its potential impact warrants immediate attention.
OpenCVE Enrichment