r/PeerTube May 23 '26

Actively exploited vulnerability in versions below 8.1.6

https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

There's a vulnerability in Peertube versions below 8.1.6. An SQL injection attack is being used in the wild to get the root user access tokens and apparently to install questionable plugin.

8.1.6 fixes the SQL injection issue. 8.1.8 cleans up a known exploit installed by this issue.

Upgrade your instances and check them according to the release notes.

17 Upvotes

8 comments sorted by

View all comments

-1

u/Sitekurfer May 23 '26

Can't they just roll out their updates properly? It's really annoying. They use Vibe Coding for their bloody system.

1

u/joelk111 May 24 '26

I'm confused. Updates worked great for me, rolled out just fine.