Arbitrary Command Execution Vulnerability in ClipBucket Video Sharing Platform
CVE-2026-42846

9.8CRITICAL

Key Information:

Vendor

Macwarrior

Vendor
CVE Published:
11 June 2026

What is CVE-2026-42846?

An arbitrary command execution vulnerability exists in ClipBucket v5 due to improper handling of URLs for the Remote Play feature. Authenticated users can exploit this flaw by importing external URLs, which are directly concatenated into shell commands without proper escaping. Consequently, any shell metacharacters in the URL can be executed, allowing attackers to run arbitrary commands on the system. This vulnerability has been addressed in version 5.5.3.

Affected Version(s)

clipbucket-v5 < 5.5.3 - #140

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.