Junglewise Threat Intelligence

CVE-2026-73211: PeerTube SQL injection in actor follow score update

CVE-2026-73211 · Severity: critical · CVSS 9.8 · Published 2026-08-11

Executive brief

PeerTube is a video streaming platform that federates content across servers using ActivityPub. A critical SQL injection flaw in the actor follow scoring logic allows any remote server to inject malicious code and gain full database access, including the ability to steal administrator authentication tokens and take over admin accounts.

Technical details

The vulnerability is a SQL injection flaw in ActorFollowModel.updateScore() where attacker-controlled ActivityPub actor inboxUrl values are interpolated directly into an SQL query without proper escaping. This requires no authentication—any remote ActivityPub-compatible server can exploit it by crafting a malicious inboxUrl parameter. Successful exploitation grants read and write access to the PeerTube database, including sensitive tables like oAuthToken containing accessToken values used for administrator authentication. The issue was patched in version 8.1.6, released May 20, 2026.

Affected products

  • PeerTube PeerTube before 8.1.6

Timeline

  • 2026-05-20: disclosed: PeerTube v8.1.6 released with SQL injection fix
  • 2026-05-20: patched: Version 8.1.6 patches the vulnerability

References