Vulnerability Description
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-hvfx-hxmr-2
- https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-hvfx-hxmr-2
FAQ
What is CVE-2026-42846?
CVE-2026-42846 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the...
How severe is CVE-2026-42846?
CVE-2026-42846 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-42846?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.