{"id":"CVE-2026-77929","published":"2026-09-18T15:17:13.287","lastModified":"2026-09-22T20:53:07.383","description":"ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://github.com/MacWarrior/clipbucket-v5/commit/61cce55ab26ef88fb782dfde47b44c17c56978cd","tags":[]},{"url":"https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182","tags":[]},{"url":"https://www.vulncheck.com/advisories/clipbucket-remote-code-execution-via-photo-upload-endpoint","tags":[]}],"exploitRefs":[{"url":"https://github.com/MacWarrior/clipbucket-v5/commit/61cce55ab26ef88fb782dfde47b44c17c56978cd","tags":[]},{"url":"https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows authenticated users to upload a PHP file that can be executed remotely, leading to potential full system compromise.","exploitability":"Exploitation is relatively straightforward for an attacker who can authenticate, as the flaw lies in the file extension validation process.","blast_radius":"If exploited, the impact could be severe, as it allows for remote code execution on the server hosting the ClipBucket application.","remediation":"Upgrade to ClipBucket v5.5.3-#182 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-required","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:24:06.584Z"}}