Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-80138: ClipBucket V5 installer lets anyone run commands on server

CVE-2026-80138 · published 9 days ago
Summary

The web installer in ClipBucket version 5 does not check a setting called php_cli_filepath before using it in a command line. This lets anyone on the internet send a specially crafted request to the installer and cause it to run any command they choose with the same rights as the website. Update to a fixed version or disable the installer until it is patched.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
macwarrior clipbucket-v5 <= 5.5.3-#153
Original advisory text
ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.
Severity
9.9 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published25 Aug 2026
Updated4 Sep 2026
First seen25 Aug 2026
Sources
CVE-2026-80138 · MITRE
Monitor software like this
Free during beta