logo

CVE-2026-77929: Authenticated File Upload Leads to Remote Code Execution in ClipBucket v5

ID: 24f0d5df-3d1c-562b-8876-9e6f5a7972f2

STIX ID: report--24f0d5df-3d1c-562b-8876-9e6f5a7972f2

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

A high-severity file upload vulnerability (CVE-2026-77929) in ClipBucket v5's FileUpload::manageFile() allowed authenticated users to upload files that passed image magic-byte checks while retaining attacker-controlled executable extensions (e.g., .php), resulting in potential remote code execution; the issue is fixed in release 5.5.3-#182 and mitigations include upgrading, auditing uploads, and hardening webserver rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.