<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>How Bad Was The PeerTube Exploit?</title>
        <link>https://video.fedihost.co/videos/watch/360875e3-7d14-410a-9e6a-d5d1e01f2486</link>
        <description>PeerTube patched a serious SQL injection and then found out that someone had already been exploiting it in the wild. The flaw sat in the ActivityPub actor score calculation, so a malicious actor name could carry SQL straight into your database, and because everything on the fediverse talks to everything else it hopped from instance to instance like an old school worm, quietly installing a fake plugin called Google Analytics JS. Victor walks through the weekend he spent patching ten infected instances while sick in bed with a modem that had just died on him, what the attacker could and could not actually reach, and why PeerTube's plugin system is the real problem sitting underneath all of it. Find Victor: @kini@maro.xyz Find Paige: @paige@canadiancivil.com</description>
        <lastBuildDate>Tue, 04 Aug 2026 19:01:56 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://video.fedihost.co</generator>
        <image>
            <title>How Bad Was The PeerTube Exploit?</title>
            <url>https://video.fedihost.co/lazy-static/avatars/c7aa8df8-26ae-4494-9eb9-eda46cfe0e5b.png</url>
            <link>https://video.fedihost.co/videos/watch/360875e3-7d14-410a-9e6a-d5d1e01f2486</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://video.fedihost.co/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://video.fedihost.co/feeds/video-comments.xml?videoId=360875e3-7d14-410a-9e6a-d5d1e01f2486" rel="self" type="application/rss+xml"/>
    </channel>
</rss>