Executive brief
ClipBucket v5 is an open-source video sharing platform. A security flaw in the subtitle management system allows a registered user to accidentally or maliciously overwrite all subtitle titles for a video they own in a single action. This results in a loss of data integrity for the affected video's captions, though it does not allow an attacker to modify videos belonging to other users.
Technical details
The vulnerability exists in the `update_subtitle()` function within `upload/includes/classes/video.class.php`. While the application uses `mysql_clean()` (which wraps `mysqli::real_escape_string()`) to prevent standard SQL injection, the database query utilizes the `LIKE` operator for the `number` field. Because `real_escape_string()` does not neutralize SQL wildcards like `%` or `_`, an authenticated attacker can provide a `%` character as the `number` parameter. This causes the `WHERE` clause to match every subtitle row associated with the `videoid`, resulting in a mass overwrite of all subtitle titles for that video. The issue is fixed in version 5.5.3 - #141 by replacing the `LIKE` operator with `=` and adding input validation.
Affected products
- MacWarrior ClipBucket v5 <= 5.5.3 - #140
Timeline
- 2026-06-03: advisory: GitHub Security Advisory published
- 2026-06-11: disclosed: CVE published to NVD
- 2026-06-11: patched: Fix released in version 5.5.3 - #141