<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PeerTube v8.1.8 is out and it&#x27;s a critical security release.]]></title><description><![CDATA[<p dir="auto">PeerTube v8.1.8 is out and it's a critical security release.<br />
The SQL injection vulnerability fixed in v8.1.6 has been actively exploited since at least May 18, 2026. Attackers used it to generate root tokens and install a malicious plugin (peertube-plugin-google-analytics-js) that loads an external script.<br />
v8.1.8 automatically removes the plugin and invalidates all OAuth tokens.<br />
<a target="_blank" rel="noopener noreferrer nofollow ugc">Release notes:</a><br />
Please update the Cloudron package as soon as possible.</p>
]]></description><link>https://forum.cloudron.io/topic/15542/peertube-v8.1.8-is-out-and-it-s-a-critical-security-release.</link><generator>RSS for Node</generator><lastBuildDate>Sat, 23 May 2026 14:18:29 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/15542.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 23 May 2026 11:40:13 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PeerTube v8.1.8 is out and it&#x27;s a critical security release. on Sat, 23 May 2026 13:57:59 GMT]]></title><description><![CDATA[<p dir="auto">thanks, one of my instances seemed to be effected by this</p>
]]></description><link>https://forum.cloudron.io/post/125054</link><guid isPermaLink="true">https://forum.cloudron.io/post/125054</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Sat, 23 May 2026 13:57:59 GMT</pubDate></item></channel></rss>