Junglewise Threat Intelligence

CVE-2026-37470: ClipBucket v5 clickjacking in Authentication interface

CVE-2026-37470 · Severity: high · CVSS 7.3 · Published 2026-05-22

Executive brief

ClipBucket, a popular open-source video sharing platform, contains a security flaw in its login interface. An attacker can trick legitimate users into performing unintended actions, such as revealing their login credentials or changing account settings, by overlaying the real website with a hidden, malicious layer. This could lead to unauthorized account access and the theft of sensitive user information.

Technical details

A clickjacking vulnerability (CWE-1021) exists in ClipBucket v5 version 5.5.2 within the authentication interface and login page endpoint. The application fails to implement adequate HTTP response security headers, such as X-Frame-Options or Content-Security-Policy (CSP) frame-ancestors, allowing the site to be rendered within an unauthorized frame or iframe. A remote attacker can exploit this by tricking a logged-in user into interacting with a malicious page that overlays the ClipBucket UI. Successful exploitation requires user interaction and can result in credential theft or unauthorized administrative actions.

Affected products

  • ClipBucket ClipBucket v5 5.5.2

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory

References