CVE-2026-7581 Details
Description
A security vulnerability has been detected in alexta69 MeTube up to 2026.04.09. This affects the function on_prepare of the file app/main.py of the component CORS Policy. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2026.04.10 is able to mitigate this issue. The identifier of the patch is 0072d3488ae5b8d922d3ee87458d829993742a32. It is recommended to upgrade the affected component.
A vulnerability in MeTube by alexta69, affecting versions prior to 2026.04.09, allows for a permissive Cross-Origin Resource Sharing (CORS) policy. The issue arises in the 'on_prepare' function of 'app/main.py', where the 'Origin' header is reflected into the 'Access-Control-Allow-Origin' response without validation. This flaw enables remote cross-origin requests from untrusted domains, potentially leading to unauthorized actions on behalf of the user.
Users are advised to upgrade to MeTube version 2026.04.10, which addresses the CORS vulnerability by implementing a proper allowlist. The latest version can be downloaded from the GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2026CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/alexta69/metube/ | [email protected] | Vendor |
| https://github.com/alexta69/metube/commit/0072d3488ae5b8d922d3ee87458d829993742a32 | [email protected] | Source CodeVendor |
| https://github.com/alexta69/metube/pull/949 | [email protected] | Issue TrackingVendor |
| https://github.com/alexta69/metube/releases/tag/2026.04.10 | [email protected] | Release NotesVendor |
| https://github.com/az10b/security-advisories/blob/main/cors_MeTube.md | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/submit/801529 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360528 | [email protected] | AdvisoryPartial Content |
| https://vuldb.com/vuln/360528/cti | [email protected] | AdvisoryPartial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
| CWE-942 | Permissive Cross-domain Policy with Untrusted Domains | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| alexta69 MeTube | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | New CVE Received | [email protected] |
Volerion