ClipBucket v5 before 5.5.3-#197 contains a path traversal...
High severity
Unreviewed
Published
Sep 25, 2026
to the GitHub Advisory Database
•
Updated Sep 25, 2026
Description
Published by the National Vulnerability Database
Sep 25, 2026
Published to the GitHub Advisory Database
Sep 25, 2026
Last updated
Sep 25, 2026
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.
References