Authorization Flaw in ClipBucket Video Sharing Platform
CVE-2026-47238
6.5MEDIUM
What is CVE-2026-47238?
ClipBucket v5, an open-source video sharing platform, is susceptible to a significant authorization flaw, wherein normal authenticated users can manipulate another user's video subtitles. This vulnerability arises from inadequate authorization checks, enabling an attacker to upload, edit, or delete subtitles associated with videos that do not belong to them. The issue has been addressed in the updated version 5.5.3, effectively mitigating the risk of unauthorized subtitle modifications. It is crucial for users running earlier versions to upgrade to the latest release to safeguard their video content.
Affected Version(s)
clipbucket-v5 < 5.5.3 - #133
