CVE-2026-100372: ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with managetemplateaccess permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated ClipBucket administrator with the manage_template_access permission can exploit it. The attacker must be able to access the admin template editor.
What access does exploitation provide?
An attacker can overwrite executable PHP files outside the intended layout directory. This can result in remote code execution as the web server user.
Which versions are affected?
ClipBucket v5 versions before 5.5.3-#197 are affected. Updating to 5.5.3-#197 or later addresses the affected version range.