ClipBucket: IDOR in videos subtitle editor
CVE-2026-47238
6.5MEDIUM
What is CVE-2026-47238?
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.
Affected Version(s)
clipbucket-v5 < 5.5.3 - #133
