๐Ÿ” CVE Alert

CVE-2026-33735

UNKNOWN 0.0

MyTube has an Improper Access Control that Allows Complete Application Takeover

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.

CWE CWE-285 CWE-639
Vendor franklioxygen
Product mytube
Published Mar 27, 2026
Last Updated Mar 27, 2026
Stay Ahead of the Next One

Get instant alerts for franklioxygen mytube

Be the first to know when new unknown vulnerabilities affecting franklioxygen mytube are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

franklioxygen / MyTube
< 1.8.69

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/franklioxygen/MyTube/security/advisories/GHSA-63cf-662x-crp2 github.com: https://github.com/franklioxygen/MyTube/commit/b7bf9b7960958c6c51f85fe50a2fc041a086c466 github.com: https://github.com/franklioxygen/MyTube/blob/6ade838a46366174e2c030f856340f3856e03132/backend/src/middleware/roleBasedSettingsMiddleware.ts#L116