This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThe release fixes a path traversal vulnerability affecting playlist and channel title handling.
Why it matters: Severity rated 90; patch immediately to protect against directory traversal attacks in Metube's media titles.
Summary
AI summaryFix prevents playlist and channel title path traversal vulnerability.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes path traversal vulnerability in playlist/channel title handling Fixes path traversal vulnerability in playlist/channel title handling Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
Docker Images
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.07.13
GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.07.13
Changes
- fix: prevent playlist/channel title path traversal (closes GHSA-vh67-38x4-w8pc) (fdfbfed)
Security Fixes
- GHSA-vh67-38x4-w8pc — prevents path traversal in playlist and channel titles
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About metube
Self-hosted video downloader for YouTube and other sites (web UI for youtube-dl / yt-dlp)
Related context
Related tools
Beta — feedback welcome: [email protected]