OS Command Injection in ClipBucket V5 Installer by MacWarrior
CVE-2026-80138
9.2CRITICAL
What is CVE-2026-80138?
The web installer of ClipBucket V5 is susceptible to OS command injection due to insufficient validation of the php_cli_filepath parameter. This vulnerability enables unauthenticated attackers to send a specifically crafted POST request, allowing them to execute arbitrary commands with the privileges of the web server user. The flaw arises from the inadequacy of the installer to properly escape or validate input, potentially leading to severe security implications.
Affected Version(s)
clipbucket-v5 5.5.1 <= 5.5.3-#153
