CVE-2026-33735
Severity CVSS v4.0:
HIGH
Type:
CWE-285
Improper Authorization
Publication date:
27/03/2026
Last modified:
31/03/2026
Description
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.
Impact
Base Score 4.0
7.40
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:* | 1.8.69 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/franklioxygen/MyTube/blob/6ade838a46366174e2c030f856340f3856e03132/backend/src/middleware/roleBasedSettingsMiddleware.ts#L116
- https://github.com/franklioxygen/MyTube/commit/b7bf9b7960958c6c51f85fe50a2fc041a086c466
- https://github.com/franklioxygen/MyTube/security/advisories/GHSA-63cf-662x-crp2
- https://github.com/franklioxygen/MyTube/security/advisories/GHSA-63cf-662x-crp2



