Skip to content

metube

v2026.06.20 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

self-hosted youtube youtube-dl yt-dlp

Affected surfaces

auth

Summary

AI summary

Fixed open download vulnerability for cookie files.

Full changelog

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.06.20

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.06.20

Changes

  • fix open download of cookie files (ce897ee)
  • upgrade dependencies (dd1b4c2)

Security Fixes

  • fix open download of cookie files (ce897ee) — prevents unauthorized access to sensitive authentication data

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track metube

Get notified when new releases ship.

Sign up free

About metube

Self-hosted video downloader for YouTube and other sites (web UI for youtube-dl / yt-dlp)

All releases →

Beta — feedback welcome: [email protected]