CVE-2026-49482: ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request. This issue has been patched in version 5.5.3 - #141.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ClipBucket v5to a version that resolves this vulnerability.Fixed in 5.5.3 - #141
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49482?
The severity of CVE-2026-49482 is medium, rated at 4.3 on the CVSS scale.
How do I fix CVE-2026-49482?
To fix CVE-2026-49482, upgrade ClipBucket to version 5.5.3 or later.
What impact does CVE-2026-49482 have on users?
CVE-2026-49482 allows authenticated users to overwrite all subtitle titles due to SQL wildcard injection.
Is CVE-2026-49482 exploitable remotely?
CVE-2026-49482 is not exploitable remotely as it requires authenticated access to the ClipBucket platform.
What versions of ClipBucket are affected by CVE-2026-49482?
CVE-2026-49482 affects ClipBucket version 5 and prior to version 5.5.3.