OS Command Injection in ClipBucket V5 Installer by MacWarrior
CVE-2026-80138

9.2CRITICAL

Key Information:

Vendor

Macwarrior

Vendor
CVE Published:
25 August 2026

What is CVE-2026-80138?

The web installer of ClipBucket V5 is susceptible to OS command injection due to insufficient validation of the php_cli_filepath parameter. This vulnerability enables unauthenticated attackers to send a specifically crafted POST request, allowing them to execute arbitrary commands with the privileges of the web server user. The flaw arises from the inadequacy of the installer to properly escape or validate input, potentially leading to severe security implications.

Affected Version(s)

clipbucket-v5 5.5.1 <= 5.5.3-#153

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Nurudini
.