Junglewise Threat Intelligence

CVE-2026-49482: MacWarrior ClipBucket SQL wildcard injection in subtitle editing endpoint

CVE-2026-49482 · Severity: medium · CVSS 4.3 · Published 2026-06-12

Technologies: MacWarrior ClipBucket. Vendors: MacWarrior.

Executive brief

ClipBucket v5 is an open-source video sharing platform. A security flaw in the subtitle management system allows a registered user to accidentally or maliciously overwrite all subtitle titles for a video they own in a single action. This results in a loss of data integrity for the affected video's captions, though it does not allow an attacker to modify videos belonging to other users.

Technical details

The vulnerability exists in the `update_subtitle()` function within `upload/includes/classes/video.class.php`. While the application uses `mysql_clean()` (which wraps `mysqli::real_escape_string()`) to prevent standard SQL injection, the database query utilizes the `LIKE` operator for the `number` field. Because `real_escape_string()` does not neutralize SQL wildcards like `%` or `_`, an authenticated attacker can provide a `%` character as the `number` parameter. This causes the `WHERE` clause to match every subtitle row associated with the `videoid`, resulting in a mass overwrite of all subtitle titles for that video. The issue is fixed in version 5.5.3 - #141 by replacing the `LIKE` operator with `=` and adding input validation.

Affected products

  • MacWarrior ClipBucket v5 <= 5.5.3 - #140

Timeline

  • 2026-06-03: advisory: GitHub Security Advisory published
  • 2026-06-11: disclosed: CVE published to NVD
  • 2026-06-11: patched: Fix released in version 5.5.3 - #141

References

Related threats