CVE-2026-77929: Authenticated File Upload Leads to Remote Code Execution in ClipBucket v5
ID: 24f0d5df-3d1c-562b-8876-9e6f5a7972f2
STIX ID: report--24f0d5df-3d1c-562b-8876-9e6f5a7972f2
Feed Name: CosmicBytez Labs
Threat Score
A high-severity file upload vulnerability (CVE-2026-77929) in ClipBucket v5's FileUpload::manageFile() allowed authenticated users to upload files that passed image magic-byte checks while retaining attacker-controlled executable extensions (e.g., .php), resulting in potential remote code execution; the issue is fixed in release 5.5.3-#182 and mitigations include upgrading, auditing uploads, and hardening webserver rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
