Browse all 11 CVE security advisories affecting chocobozzz. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Chocobozzz develops the open-source media server PeerTube, which enables decentralized video hosting. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and improper access controls. Notable security characteristics include a focus on decentralized architecture reducing single points of failure, though past incidents have involved XSS vulnerabilities in video upload mechanisms and RCE in API endpoints. The project maintains a moderate CVE count with eight records, reflecting ongoing security improvements in a complex web application environment.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-73211 | PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() — PeerTubeCWE-89 | 9.8 | Critical | 2026-08-11 |
| CVE-2026-73090 | PeerTube: Cross-origin remote video takeover via Update activity — PeerTubeCWE-863 | 9.3 | Critical | 2026-08-11 |
| CVE-2026-57167 | PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) — PeerTubeCWE-80 | - | - | 2026-07-10 |
This page lists every published CVE security advisory associated with chocobozzz. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.