Mass Assignment Vulnerability in MyTube Affects Multiple Versions
CVE-2026-24140
What is CVE-2026-24140?
MyTube, a self-hosted downloader and player for video websites, is susceptible to a mass assignment vulnerability in its settings management feature. Versions 1.7.78 and earlier do not properly validate input data received in the saveSettings() function, allowing attackers to inject arbitrary key-value pairs. This means that any field sent by an attacker can be directly saved to the database, regardless of whether it is a legitimate setting, potentially compromising the application's integrity and leading to unauthorized changes. This vulnerability has been rectified in version 1.7.79.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MyTube < 1.7.79
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
