Impact
The vulnerability resides in the Cookie File Handler component of MeTube. An unknown function related to the /download/.metube/cookies.txt file permits manipulation that allows a remote attacker to read files or directories. This is an instance of improper restriction of operations, as indicated by CWE-425, and a directory traversal or file disclosure flaw, as indicated by CWE-552. Because the exploit is publicly disclosed, attackers could compromise confidentiality by retrieving arbitrary files without needing local privileges.
Affected Systems
Affected products include the MeTube application from alexta69, versions up to and including 2026.06.10. The issue is fixed in version 2026.06.20. The patch identifier is ce897ee00903bf7ded406f0d7852d95dd4164add. The affected component is the Cookie File Handler, specifically the handling of the .metube/cookies.txt file within the /download/ folder.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but it remains publicly disclosed. The attack can be triggered remotely without authentication, as the CVE description does not mention any required privileges. Because the flaw allows arbitrary file access, the risk is significant for confidentiality. A timely patch is therefore strongly recommended.
OpenCVE Enrichment