This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThe release blocks SSRF attacks originating from user‑submitted URLs.
Why it matters: With a severity score of 90, mitigating SSRF is critical for all services handling external links; operators must update immediately to prevent exploitation.
Summary
AI summaryBlock SSRF via user‑submitted URLs.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
block SSRF via user-submitted URLs block SSRF via user-submitted URLs Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
add AlbumArtistPostProcessor to fill missing album-artist metadata add AlbumArtistPostProcessor to fill missing album-artist metadata Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | Low |
upgrade dependencies upgrade dependencies Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
prefer topic channel for album artist prefer topic channel for album artist Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
Docker Images
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.07.16
GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.07.16
Changes
- upgrade dependencies (8071611)
- fix: prefer topic channel for album artist (220f991)
- fix: block SSRF via user-submitted URLs (6d05287)
- feat: add AlbumArtistPostProcessor to fill missing album-artist metadata (c104e30)
Security Fixes
- fix: block SSRF via user‑submitted URLs (commit 6d05287)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About metube
Self-hosted video downloader for YouTube and other sites (web UI for youtube-dl / yt-dlp)
Related context
Related tools
Beta — feedback welcome: [email protected]