CVE-2026-82813
Received Received - Intake

Authentication Bypass in TubeBuddy Chrome Extension

Vulnerability report for CVE-2026-82813, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ben_group tubebuddy to 5.8.4 (inc)
ben_group tubebuddy to 5.8.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the TubeBuddy for YouTube Chrome extension up to version 5.8.4. It allows an attacker to overwrite authentication tokens by manipulating URL parameters without proper validation. The issue occurs in the TBGlobal.GetToken function where the extension reads unvalidated query parameters t, c, and r from a redirect URL handler. This can corrupt the extension's authentication state and potentially disrupt functionality.

Detection Guidance

Check for suspicious network traffic involving tubebuddy.com/redirect URLs with parameters t, c, or r. Inspect Chrome extension storage for unexpected token values under keys like tubebuddyToken-<channel ID>. Review browser logs for unauthorized redirects or token modifications.

Impact Analysis

An attacker could craft a malicious URL that forces the extension to store an attacker-controlled token for your channel. This could disrupt functionality or cause denial of service for your channel. Additionally, the vulnerability enables open redirect attacks, which could be used for phishing by disguising malicious links as legitimate TubeBuddy URLs.

Mitigation Strategies

Disable or remove the TubeBuddy extension version 5.8.4. Update to the latest version if a patch is available. Avoid clicking untrusted TubeBuddy links. Monitor for unusual authentication errors or channel access issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82813. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart