CVE-2026-78051
Received Received - Intake

Path Traversal in MeTube

Vulnerability report for CVE-2026-78051, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-23

Last updated on: 2026-08-23

Assigner: VulDB

Description

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-23
Last Modified
2026-08-23
Generated
2026-08-23
AI Q&A
2026-08-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
alexta69 metube to 2026.06.10|start_including=2026.06.20 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-425 The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthorized access to the cookies.txt file in MeTube up to version 2026.06.10. The file contains sensitive user session cookies and is accessible via the /download/.metube/cookies.txt URI due to improper access restrictions in the /download/.metube endpoint.

Detection Guidance

Check if the vulnerable file /download/.metube/cookies.txt is accessible by attempting to access it via a web browser or using curl commands like 'curl http://<metube-server>/download/.metube/cookies.txt'. If the file is readable, the system is vulnerable.

Impact Analysis

Attackers can access your cookies.txt file, steal session cookies, and hijack your MeTube account or other accounts where those cookies are used. This could lead to unauthorized actions on your behalf without needing your password.

Compliance Impact

This vulnerability may violate GDPR and HIPAA by exposing sensitive user data (cookies) without authorization. It could lead to unauthorized access to personal information, triggering compliance violations related to data protection and user privacy.

Mitigation Strategies

Upgrade MeTube to version 2026.06.20 or later. If immediate upgrade is not possible, restrict access to the /download/.metube endpoint by configuring proper access controls or firewall rules to block unauthorized access to sensitive files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78051. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart