peertube: fix security issue

This issue doesn't have a CVE yet.
For context, see:
- https://github.com/Chocobozzz/PeerTube/releases/
- https://github.com/Chocobozzz/PeerTube/issues/7622

Not-cherry-picked-because: v7 on stable doesn't have a patch release, but v8 on master has one
This commit is contained in:
ppom
2026-05-23 12:00:00 +02:00
parent 2c1a6bd414
commit de9575c19f
2 changed files with 32 additions and 0 deletions

View File

@@ -56,6 +56,11 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-WbZFOOvX6WzKB9tszxJl6z+V6cDBH6Y2SjoxF17WvUo=";
};
patches = [
# https://github.com/Chocobozzz/PeerTube/issues/7622
./sql-injection-fix.patch
];
yarnOfflineCacheServer = fetchYarnDeps {
yarnLock = "${finalAttrs.src}/yarn.lock";
hash = "sha256-T1stKz8+1ghQBJB8kujwcqmygMdoswjFBL/QWAHSis0=";

View File

@@ -0,0 +1,27 @@
diff --git i/server/core/models/actor/actor-follow.ts w/server/core/models/actor/actor-follow.ts
index 6852a0b3a..807ebcfdb 100644
--- i/server/core/models/actor/actor-follow.ts
+++ w/server/core/models/actor/actor-follow.ts
@@ -633,20 +633,8 @@ export class ActorFollowModel extends SequelizeModel<ActorFollowModel> {
}
}
- static updateScore (inboxUrl: string, value: number, t?: Transaction) {
- const query = `UPDATE "actorFollow" SET "score" = LEAST("score" + ${value}, ${ACTOR_FOLLOW_SCORE.MAX}) ` +
- 'WHERE id IN (' +
- 'SELECT "actorFollow"."id" FROM "actorFollow" ' +
- 'INNER JOIN "actor" ON "actor"."id" = "actorFollow"."actorId" ' +
- `WHERE "actor"."inboxUrl" = '${inboxUrl}' OR "actor"."sharedInboxUrl" = '${inboxUrl}'` +
- ')'
-
- const options = {
- type: QueryTypes.BULKUPDATE,
- transaction: t
- }
-
- return ActorFollowModel.sequelize.query(query, options)
+ static updateScore (_inboxUrl: string, _value: number, _t?: Transaction) {
+ return
}
static async updateScoreByFollowingServers (serverIds: number[], value: number, t?: Transaction) {