CVE-2026-78051

Source
https://cve.org/CVERecord?id=CVE-2026-78051
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78051.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78051
Aliases
  • GHSA-hj5g-p3v4-3cw5
Published
2026-08-22T23:30:11Z
Modified
2026-08-27T11:30:37Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
alexta69 MeTube Cookie File cookies.txt file access
Details

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-425",
        "CWE-552"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78051.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2026.06.1"
                },
                {
                    "last_affected": "2026.06.1"
                },
                {
                    "introduced": "2026.06.2"
                },
                {
                    "last_affected": "2026.06.2"
                },
                {
                    "introduced": "2026.06.3"
                },
                {
                    "last_affected": "2026.06.3"
                },
                {
                    "introduced": "2026.06.4"
                },
                {
                    "last_affected": "2026.06.4"
                },
                {
                    "introduced": "2026.06.5"
                },
                {
                    "last_affected": "2026.06.5"
                },
                {
                    "introduced": "2026.06.6"
                },
                {
                    "last_affected": "2026.06.6"
                },
                {
                    "introduced": "2026.06.7"
                },
                {
                    "last_affected": "2026.06.7"
                },
                {
                    "introduced": "2026.06.8"
                },
                {
                    "last_affected": "2026.06.8"
                },
                {
                    "introduced": "2026.06.9"
                },
                {
                    "last_affected": "2026.06.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/alexta69/metube

Affected ranges

Type
GIT
Repo
https://github.com/alexta69/metube
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2026.06.0"
        },
        {
            "last_affected": "2026.06.0"
        },
        {
            "introduced": "2026.06.10"
        },
        {
            "last_affected": "2026.06.10"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2026.*
2026.06.0
2026.06.06
2026.06.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78051.json"