CVE-2026-78051: alexta69 MeTube Cookie File cookies.txt file access
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
alexta69 MeTubeto a version that resolves this vulnerability.Fixed in 2026.06.20Patch ce897ee00903bf7ded406f0d7852d95dd4164add - Compensating control
Since the attack can be initiated remotely and exploit is publicly disclosed, restrict network/firewall access to the MeTube instance until upgraded to 2026.06.20.
Event History
Frequently Asked Questions
Which deployments are affected?
MeTube versions up to and including 2026.06.10 are affected. Upgrading to version 2026.06.20 resolves the issue.
Does exploitation require authentication or user interaction?
The vulnerability can be initiated remotely. The provided severity vector indicates no privileges or user interaction are required.
How serious is the exposed data risk?
The issue allows access to files or directories through the Cookie File Handler path /download/.metube/cookies.txt. The supplied vector indicates low confidentiality impact and no integrity or availability impact.
Is there evidence that attackers may use this issue?
A public exploit has been disclosed and may be used. Prioritize upgrading affected internet-accessible deployments.
What should be done to remediate it?
Upgrade alexta69 MeTube to version 2026.06.20 or later. The listed patch is ce897ee00903bf7ded406f0d7852d95dd4164add.