Home

Description

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.

PUBLISHED Reserved 2026-05-18 | Published 2026-06-11 | Updated 2026-06-13 | Assigner GitHub_M




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-639: Authorization Bypass Through User-Controlled Key

CWE-863: Incorrect Authorization

Product status

< 5.5.3 - #133
affected

References

github.com/...ket-v5/security/advisories/GHSA-x468-whmw-c863 exploit

github.com/...ket-v5/security/advisories/GHSA-x468-whmw-c863

cve.org (CVE-2026-47238)

nvd.nist.gov (CVE-2026-47238)

Download JSON