Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Fediverse
  3. PeerTube
  4. **v8.1.8 Important security upgrade**

**v8.1.8 Important security upgrade**

Scheduled Pinned Locked Moved PeerTube
7 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • peertube@framapiaf.orgP This user is from outside of this forum
    peertube@framapiaf.orgP This user is from outside of this forum
    peertube@framapiaf.org
    wrote last edited by
    #1

    **v8.1.8 Important security upgrade**

    We have learned that the SQL injection vulnerability fixed in v8.1.6 has been exploited at scale since at least May 18, 2026 and so before the v8.1.6 release.

    We released a new version that remove all user token access gained before v8.1.6. We also explain the attack in the changelog and the countermeasures taken by this release.

    **Please upgrade to v8.1.8 as soon as possible.**

    https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

    john_livingston@mamot.frJ oliviavespera@spacey.spaceO benjamin@piaille.frB shadowwwind@mastodon.socialS 4 Replies Last reply
    0
    • peertube@framapiaf.orgP peertube@framapiaf.org

      **v8.1.8 Important security upgrade**

      We have learned that the SQL injection vulnerability fixed in v8.1.6 has been exploited at scale since at least May 18, 2026 and so before the v8.1.6 release.

      We released a new version that remove all user token access gained before v8.1.6. We also explain the attack in the changelog and the countermeasures taken by this release.

      **Please upgrade to v8.1.8 as soon as possible.**

      https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

      john_livingston@mamot.frJ This user is from outside of this forum
      john_livingston@mamot.frJ This user is from outside of this forum
      john_livingston@mamot.fr
      wrote last edited by
      #2

      @peertube
      What is the first vulnerable version?

      peertube@framapiaf.orgP 1 Reply Last reply
      0
      • john_livingston@mamot.frJ john_livingston@mamot.fr

        @peertube
        What is the first vulnerable version?

        peertube@framapiaf.orgP This user is from outside of this forum
        peertube@framapiaf.orgP This user is from outside of this forum
        peertube@framapiaf.org
        wrote last edited by
        #3

        @John_Livingston All versions < 8.1.6 are vulnerable

        1 Reply Last reply
        0
        • peertube@framapiaf.orgP peertube@framapiaf.org

          **v8.1.8 Important security upgrade**

          We have learned that the SQL injection vulnerability fixed in v8.1.6 has been exploited at scale since at least May 18, 2026 and so before the v8.1.6 release.

          We released a new version that remove all user token access gained before v8.1.6. We also explain the attack in the changelog and the countermeasures taken by this release.

          **Please upgrade to v8.1.8 as soon as possible.**

          https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

          oliviavespera@spacey.spaceO This user is from outside of this forum
          oliviavespera@spacey.spaceO This user is from outside of this forum
          oliviavespera@spacey.space
          wrote last edited by
          #4

          @peertube Who's been affected by this and how did you learn about this?

          1 Reply Last reply
          0
          • peertube@framapiaf.orgP peertube@framapiaf.org

            **v8.1.8 Important security upgrade**

            We have learned that the SQL injection vulnerability fixed in v8.1.6 has been exploited at scale since at least May 18, 2026 and so before the v8.1.6 release.

            We released a new version that remove all user token access gained before v8.1.6. We also explain the attack in the changelog and the countermeasures taken by this release.

            **Please upgrade to v8.1.8 as soon as possible.**

            https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

            benjamin@piaille.frB This user is from outside of this forum
            benjamin@piaille.frB This user is from outside of this forum
            benjamin@piaille.fr
            wrote last edited by
            #5

            @peertube thanks for the transparent and precise report
            and the quick and efficient reaction
            ❤

            a pleasure ❤

            1 Reply Last reply
            0
            • peertube@framapiaf.orgP peertube@framapiaf.org

              **v8.1.8 Important security upgrade**

              We have learned that the SQL injection vulnerability fixed in v8.1.6 has been exploited at scale since at least May 18, 2026 and so before the v8.1.6 release.

              We released a new version that remove all user token access gained before v8.1.6. We also explain the attack in the changelog and the countermeasures taken by this release.

              **Please upgrade to v8.1.8 as soon as possible.**

              https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8

              shadowwwind@mastodon.socialS This user is from outside of this forum
              shadowwwind@mastodon.socialS This user is from outside of this forum
              shadowwwind@mastodon.social
              wrote last edited by
              #6

              @peertube hey @funfacts_de, security release für peertube ^

              1 Reply Last reply
              0
              • peertube@framapiaf.orgP This user is from outside of this forum
                peertube@framapiaf.orgP This user is from outside of this forum
                peertube@framapiaf.org
                wrote last edited by
                #7

                @gunchleoc You can delete existing tokens on /admin/settings/system/runners/registration-tokens-list

                If you didn't enable remote runners, you don't need to do this.

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups