CRITICAL 9.2 NVD
CVE-2026-80138
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attacker
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.
References
- https://github.com/MacWarrior/clipbucket-v5
- https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/cb_install/functions_
- https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/includes/classes/syst
- https://github.com/MacWarrior/clipbucket-v5/commit/36e7c6cfd81f62a091d2aeef96a8fc2fc2d85dc
- https://www.vulncheck.com/advisories/clipbucket-v5-5.5.1-through-5.5.3-153-os-command-inje
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-25 via NVD.
Risk Timeline
CVE Disclosed2026-08-25 · 0 days ago
Remediation Resources
vulnfeed aggregates 11369 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.