ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user. | |
| Title | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | |
| First Time appeared |
Clip-bucket
Clip-bucket clipbucket |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Clip-bucket
Clip-bucket clipbucket |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T22:12:23.914Z
Reserved: 2026-08-25T20:23:31.117Z
Link: CVE-2026-80138
No data.
Status : Received
Published: 2026-08-25T23:17:59.860
Modified: 2026-08-25T23:17:59.860
Link: CVE-2026-80138
No data.
OpenCVE Enrichment
Updated: 2026-08-26T02:30:04Z
Weaknesses