CVE-2026-33735

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-03-27 01:16

Updated : 2026-03-30 13:26


NVD link : CVE-2026-33735

Mitre link : CVE-2026-33735

CVE.ORG link : CVE-2026-33735


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key