Skip to content

PeerTube

v8.1.6 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 14d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

activitypub angular decentralized p2p video

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Fix SQL injection in actor inbox URL, reject malicious JSON‑LD objects, restrict role assignments to admins.

Changes in this release

Security Medium

Fix SQL injection from actor inbox URL during follow score updates.

Fix SQL injection from actor inbox URL during follow score updates.

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

Security Medium

Reject JSON-LD objects with special properties.

Reject JSON-LD objects with special properties.

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

Security Medium

Prevent external auth token replay attacks.

Prevent external auth token replay attacks.

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

Security Medium

Prevent SSRF on import and channel sync operations.

Prevent SSRF on import and channel sync operations.

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: low

Breaking Medium

Restricts role assignment to administrators only.

Restricts role assignment to administrators only.

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: high

Feature Medium

Stricter rate limit for password reset requests.

Stricter rate limit for password reset requests.

Source: granite4.1:8b-q6_K@2026-05-20

Confidence: high

Full changelog

IMPORTANT NOTES

  • Follow v8.1.0 IMPORTANT NOTES if you upgrade from PeerTube <= v8.0.2

SECURITY

  • Fix SQL injection coming from actor inbox URL when updating actor follow scores. Thanks to Nagarajan Selvaraj Paulmony for reporting this vulnerability :pray:
  • Reject JSON-LD objects with special properties. Thanks to Mastodon security team for reporting this vulnerability :pray:
  • Restricts role assignment to administrators only
  • Prevent external auth token replay
  • Prevent SSRF on import and channel sync
  • Stricter rate limit to ask password reset

Security Fixes

  • Fix SQL injection in actor inbox URL when updating actor follow scores
  • Reject JSON-LD objects with special properties

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track PeerTube

Get notified when new releases ship.

Sign up free

About PeerTube

ActivityPub-federated video streaming platform using P2P directly in your web browser

All releases →

Related context

Earlier breaking changes

  • v8.2.0 Drops iOS support for versions < 15.4
  • v8.2.0 Removes support for NodeJS 20; requires upgrade to NodeJS 22 (>=22.12)

Beta — feedback welcome: [email protected]