Description
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-x468-whmw-c863
Scores
CVSS v3
6.5
EPSS
0.0020
EPSS Percentile
9.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
CWE-863
Status
published
Products (1)
MacWarrior/clipbucket-v5
< 5.5.3 - #133
Published
Jun 11, 2026
Tracked Since
Jun 12, 2026