Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-77929: ClipBucket lets attackers run code through photo upload

CVE-2026-77929 · published 10 days ago
Summary

The ClipBucket video sharing software lets logged‑in users upload files. Because the system does not correctly change the file type after checking the content, a user can upload a disguised PHP script that the server will execute when the file is accessed. Update ClipBucket to the latest version or apply the vendor’s patch to stop this behavior.

What to do
  • Update macwarrior clipbucket-v5 to version 5.5.3-#182 or later.
Affected software
VendorProductAffected versions
macwarrior clipbucket-v5 < 5.5.3-#182
Original advisory text
ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.
Severity
8.7 High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published18 Sep 2026
Updated29 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-77929 · MITRE
Track software like this
Free during beta