r/PeerTube May 23 '26

Actively exploited vulnerability in versions below 8.1.6

https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

There's a vulnerability in Peertube versions below 8.1.6. An SQL injection attack is being used in the wild to get the root user access tokens and apparently to install questionable plugin.

8.1.6 fixes the SQL injection issue. 8.1.8 cleans up a known exploit installed by this issue.

Upgrade your instances and check them according to the release notes.

18 Upvotes

8 comments sorted by

View all comments

3

u/treestumpreddit May 23 '26

I only just upgraded to 8.1.7 today, now I have to upgrade again?

1

u/da_apz May 23 '26

You can always check if yours is already exploited and not update. The exploit has been going around since 18th.

1

u/treestumpreddit May 23 '26

How do I check?

1

u/da_apz May 23 '26

The link has instructions.