Description
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.
Published: 2026-08-22
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Cookie File Handler component of MeTube. An unknown function related to the /download/.metube/cookies.txt file permits manipulation that allows a remote attacker to read files or directories. This is an instance of improper restriction of operations, as indicated by CWE-425, and a directory traversal or file disclosure flaw, as indicated by CWE-552. Because the exploit is publicly disclosed, attackers could compromise confidentiality by retrieving arbitrary files without needing local privileges.

Affected Systems

Affected products include the MeTube application from alexta69, versions up to and including 2026.06.10. The issue is fixed in version 2026.06.20. The patch identifier is ce897ee00903bf7ded406f0d7852d95dd4164add. The affected component is the Cookie File Handler, specifically the handling of the .metube/cookies.txt file within the /download/ folder.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but it remains publicly disclosed. The attack can be triggered remotely without authentication, as the CVE description does not mention any required privileges. Because the flaw allows arbitrary file access, the risk is significant for confidentiality. A timely patch is therefore strongly recommended.

Generated by OpenCVE AI on August 23, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MeTube to version 2026.06.20 or later to apply the ce897ee00903bf7ded406f0d7852d95dd4164add patch.
  • Restrict file system permissions so that the /download/.metube/cookies.txt file and its parent directory are only writable and readable by the MeTube service account, preventing remote users from accessing these paths.
  • Monitor for any unauthorized file access attempts within the MeTube installation and enforce logging to detect potential exploitation attempts.

Generated by OpenCVE AI on August 23, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.
Title alexta69 MeTube Cookie File cookies.txt file access
First Time appeared Alexta69
Alexta69 metube
Weaknesses CWE-425
CWE-552
CPEs cpe:2.3:a:alexta69:metube:*:*:*:*:*:*:*:*
Vendors & Products Alexta69
Alexta69 metube
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-22T23:30:11.318Z

Reserved: 2026-08-22T08:19:17.709Z

Link: CVE-2026-78051

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-23T00:16:50.763

Modified: 2026-08-23T00:16:50.763

Link: CVE-2026-78051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T00:30:17Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')

  • CWE-552

    Files or Directories Accessible to External Parties