CVE 9.8 CRITICAL

ClipBucket: Remote Play URL Command Injection_CVE-2026-42846

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140.

AI Analysis

Arbitrary command execution via Remote Play feature

Basic Information

ID CVE-2026-42846
Source GitHub_M
Published Jun 11, 2026 at 22:49

Affected Product

Vendor MacWarrior
Product clipbucket-v5
Version < 5.5.3 - #140
Affected Versions MacWarrior clipbucket-v5 < 5.5.3 - #140

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor MacWarrior
Product ClipBucket
Version < 5.5.3 - #140

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.