Junglewise Threat Intelligence

CVE-2026-42846: MacWarrior ClipBucket OS command injection in Remote Play

CVE-2026-42846 · Severity: critical · CVSS 9.8 · Published 2026-06-11

Technologies: MacWarrior ClipBucket. Vendors: MacWarrior.

Executive brief

ClipBucket, an open-source video sharing platform, contains a security flaw in its Remote Play feature. This feature allows users to add videos by providing a web link; however, the system does not properly check these links before processing them. An attacker can use a specially crafted link to take complete control of the video server, potentially leading to the theft of user data, service disruption, or the installation of malicious software.

Technical details

An OS command injection vulnerability exists in ClipBucket v5 (prior to version 5.5.3 - #140) within the Remote Play functionality. The application accepts a user-provided URL via the 'remote_play_url' parameter and passes it to shell commands (such as ffprobe and mediainfo) using string concatenation without proper escaping. Because the input is executed via shell_exec(), an attacker can include shell metacharacters (e.g., $(...)) in the URL to achieve arbitrary code execution. While the application performs some URL validation and SSRF checks, it fails to neutralize characters that trigger command execution. This allows an authenticated attacker (including self-registered users) to gain full control over the underlying server. The issue is patched in version 5.5.3 - #140.

Affected products

  • MacWarrior ClipBucket <= 5.5.3 - #139

Timeline

  • 2026-05-27: advisory: Vendor advisory published on GitHub
  • 2026-06-11: disclosed: CVE published to NVD

References

Related threats