Sceawere

Vulnerability Detail

CVE-2026-82813UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TubeBuddy Extension Insufficient Token Validation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
12h ago
Vendor
BEN Group
Product
TubeBuddy for YouTube Extension
Attack Type
Insufficient Verification of Data Authenticity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-31T18:17:24.110Z",
  "pubdate": "2026-08-31T18:17:24.110Z",
  "executiveSummary": "A critical vulnerability exists in the BEN Group TubeBuddy for YouTube extension for Chrome, affecting versions up to 5.8.4.\nThe vulnerability stems from insufficient verification of data authenticity within the TBGlobal.GetToken function located in tubebuddymaster1.js.\nBy manipulating specific function arguments—identified as t, c, or r—an unauthenticated remote attacker can bypass integrity checks.\nThis flaw allows for the compromise of authentication tokens, posing a significant risk to user account integrity and session security.\nGiven that the exploit is public, the risk level is elevated, necessitating immediate attention to prevent unauthorized access to YouTube creator accounts or associated service data.\nThe attack can be executed remotely, requiring no specific user interaction if the victim navigates to a malicious context or if the extension context is targeted directly.",
  "technicalDetails": "The vulnerability resides within the tubebuddymaster1.js script of the TubeBuddy extension, specifically targeting the TBGlobal.GetToken function.\nThe root cause is an improper validation mechanism for the input parameters t, c, and r. These parameters appear to be integral to the generation or retrieval of authentication tokens used by the extension to communicate with backend services.\nIn a standard implementation, these arguments should undergo strict cryptographic validation or origin verification to ensure that the token request is legitimate and the data source is trusted.\nHowever, the current implementation fails to perform sufficient integrity checks, allowing an attacker to supply maliciously crafted values for these arguments.\nThe attack flow involves an adversary injecting or intercepting the parameters supplied to TBGlobal.GetToken. Because the application logic relies on these tainted inputs without secondary validation of their authenticity, the function incorrectly processes the manipulated data as legitimate.\nThis behavior results in the potential issuance of invalid, unauthorized, or spoofed tokens, which could be utilized to impersonate a legitimate user or hijack active sessions.\nBecause the extension operates within the browser environment, a remote attacker can potentially trigger this vulnerability by leveraging cross-origin communication channels or by hosting malicious scripts that interact with the extension's exported functionality.\nThe exploitation path does not require high-level system privileges or local access, making it highly accessible for remote exploitation. Once the malicious token is obtained, the post-exploitation impact includes the potential for unauthorized data exfiltration, modification of YouTube metadata, or unauthorized access to sensitive API endpoints utilized by the TubeBuddy platform.\nThe absence of rigorous input sanitization and token origin verification in TBGlobal.GetToken effectively negates the security controls intended to protect the authentication lifecycle of the extension.\nThe impact is magnified by the browser-based nature of the extension, as successful exploitation results in the compromise of the extension's security context, potentially affecting all sites where the extension is active and authenticated."
}
CVE-2026-82813: TubeBuddy Extension Insufficient Token Validation (MEDIUM Severity, CVSS: 5.4) - Sceawere