VYPR
Low severity2.7OSV Advisory· Published Jan 24, 2026· Updated Jun 17, 2026

CVE-2026-24140

CVE-2026-24140

Description

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() function accepts arbitrary key-value pairs without validating property names against allowed settings. The function uses Record<string, any> as input type and iterates over all entries using Object.entries() without filtering unauthorized properties. Any field sent by the attacker is directly persisted to the database, regardless of whether it corresponds to a legitimate application setting. This issue has been fixed in version 1.7.78.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Franklioxygen/MytubeOSV2 versions
    v1.3.15, v1.3.16, v1.3.17, …+ 1 more
    • (no CPE)range: v1.3.15, v1.3.16, v1.3.17, …
    • cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:*range: <1.7.78
  • MyTube/MyTubellm-create
    Range: <=1.7.78
  • GitHub/MyTubellm-create
    Range: <=1.7.78

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.