CVE-2026-24140

LOW

MyTube < 1.7.78 - Mass Assignment via Settings Management

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-24140. PoCs published by p1ngul1n0.

AI-analyzed exploit summary The repository contains a functional proof-of-concept for CVE-2026-24140, demonstrating a Mass Assignment vulnerability in the settings management functionality. The provided curl command exploits insufficient input validation to inject arbitrary configuration entries into the database.

Description

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() function accepts arbitrary key-value pairs without validating property names against allowed settings. The function uses Record<string, any> as input type and iterates over all entries using Object.entries() without filtering unauthorized properties. Any field sent by the attacker is directly persisted to the database, regardless of whether it corresponds to a legitimate application setting. This issue has been fixed in version 1.7.78.

Exploits (1)

github WORKING POC 1 stars
by p1ngul1n0 · poc
https://github.com/p1ngul1n0/security-research/tree/main/CVE-2026-24140.md

The repository contains a functional proof-of-concept for CVE-2026-24140, demonstrating a Mass Assignment vulnerability in the settings management functionality. The provided curl command exploits insufficient input validation to inject arbitrary configuration entries into the database.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: MyTube (version not specified)
No auth needed
Prerequisites: Access to the target API endpoint
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Scores

CVSS v3 2.7
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-915
Status published
Products (1)
franklioxygen/mytube < 1.7.78
Published Jan 24, 2026
Tracked Since Feb 18, 2026