PatchSiren

Chocobozzz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Chocobozzz CVE published 2026-08-11

CVE-2026-73211

A critical vulnerability was discovered in PeerTube, an ActivityPub-federated video streaming platform. The issue, tracked as CVE-2026-73211, allows an unauthenticated remote server to read and write PeerTube database tables by interpolating the attacker-controlled ActivityPub actor inboxUrl into an SQL query. This could lead to the takeover of administrator accounts. The vulnerability is fixed in version 8.1.6.

CRITICAL Chocobozzz CVE published 2026-08-11

CVE-2026-73090

A critical vulnerability was found in PeerTube, a video streaming platform, which allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server. This issue, fixed in version 8.2.2, has a CVSS score of 9.3 and is considered critical. The vulnerability exists due to the lack of verification of the byActor.url in processUpdateActivity and processUpdate [truncated]

MEDIUM Chocobozzz CVE published 2026-07-10

CVE-2026-57167

PeerTube, an ActivityPub-federated video streaming platform, had a vulnerability in server-side-rendered video watch pages prior to version 8.2.2. The platform embeds a schema.org JSON-LD block by JSON.stringify-ing video metadata without escaping less-than, greater-than, or slash characters, allowing a value containing the byte sequence that closes a script element to inject arbitrary HTML or JavaScript [truncated]