CVE-2026-82813
BEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetToken data authenticity
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
| CWE | CWE-345 |
| Vendor | ben group |
| Product | tubebuddy for youtube extension |
| Published | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for ben group tubebuddy for youtube extension
Be the first to know when new medium vulnerabilities affecting ben group tubebuddy for youtube extension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
BEN Group / TubeBuddy for YouTube Extension
5.8.0 5.8.1 5.8.2 5.8.3 5.8.4
References
vuldb.com: https://vuldb.com/vuln/397231 vuldb.com: https://vuldb.com/vuln/397231/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82813 vuldb.com: https://vuldb.com/submit/875303 github.com: https://github.com/xryj920/chrome_extensions/blob/main/BEN%20Group%2C%20Inc.%20TubeBuddy%20for%20YouTube%205.8.4%20allows%20authentication%20token%20overwrite%20through%20an%20unauthenticated%20redirect%20URL%20handler
Credits
๐ DRXYJ (VulDB User) VulDB CNA Team