{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/clipbucket-v5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-80138"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["clipbucket-v5"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","web-application-vulnerability"],"_cs_type":"threat","_cs_vendors":["MacWarrior"],"content_html":"\u003cp\u003eClipBucket V5 (versions 5.5.1 through 5.5.3-#153) contains a critical OS command injection vulnerability (CVE-2026-80138) within its web-based installation script. The vulnerability resides in the handling of the 'php_cli_filepath' parameter, which is processed by the installer's 'cb_install/functions_install.php' file. Because the application fails to perform adequate validation or sanitization of this user-supplied input before passing it to system-level shell execution functions, an unauthenticated attacker can supply crafted input to execute arbitrary OS commands.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation results in command execution with the privileges of the web server user. This vulnerability is particularly dangerous because it affects the initial setup phase of the application, potentially allowing an attacker to compromise the host before the administrator completes the installation process. Defenders should prioritize auditing web installer access and ensuring that software deployment instances are not exposed to the public internet during the configuration phase.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target server running an unconfigured or accessible ClipBucket V5 installer.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP POST request to the web installer endpoint (typically located in the /cb_install/ directory).\u003c/li\u003e\n\u003cli\u003eAttacker injects shell metacharacters (e.g., ;, |, \u0026amp;\u0026amp;, `) into the 'php_cli_filepath' POST parameter.\u003c/li\u003e\n\u003cli\u003eThe 'cb_install/functions_install.php' script receives the malicious input without validation.\u003c/li\u003e\n\u003cli\u003eThe application passes the unsanitized string directly to a system shell execution function.\u003c/li\u003e\n\u003cli\u003eThe underlying web server process (e.g., www-data, apache, or iis apppool) executes the injected commands.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution to drop a web shell, exfiltrate data, or pivot within the environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an unauthenticated remote attacker full control over the web server process. In a typical web hosting environment, this facilitates unauthorized access to the application source code, configuration files (containing database credentials), and potentially the ability to move laterally into the internal network. Given the critical CVSS 9.8 score, this vulnerability represents a high risk of total system compromise for any organization running affected versions of ClipBucket.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict public access to the ClipBucket installation directory (/cb_install/) using web server authentication or network-level firewall controls.\u003c/li\u003e\n\u003cli\u003eUpgrade to a version of ClipBucket V5 that incorporates the fix provided in commit 36e7c6cfd81f62a091d2aeef96a8fc2fc2d85dc4.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST requests directed at the installer file path, specifically looking for shell-related special characters in the 'php_cli_filepath' parameter.\u003c/li\u003e\n\u003cli\u003eDeploy the provided detection rule to monitor for exploitation attempts targeting the identified installer vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T00:51:23Z","date_published":"2026-08-26T00:51:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-clipbucket-rce/","summary":"ClipBucket V5 versions 5.5.1 through 5.5.3-#153 contain an OS command injection vulnerability in the web installer, allowing unauthenticated remote code execution via the php_cli_filepath parameter.","title":"OS Command Injection in ClipBucket V5 Installer","url":"https://feed.craftedsignal.io/briefs/2026-08-clipbucket-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Clipbucket-V5","version":"https://jsonfeed.org/version/1.1"}