CVE-2026-25728
EUVD-2026-705110.02.2026, 18:16
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability exists in ClipBucket's avatar and background image upload functionality. The application moves uploaded files to a web-accessible location before validating them, creating a window where an attacker can execute arbitrary PHP code before the file is deleted. The uploaded file was moved to a web-accessible path via move_uploaded_file(), then validated via ValidateImage(). If validation failed, the file was deleted via @unlink(). This vulnerability is fixed in 5.5.3 - #40.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| oxygenz | clipbucket | 5.3 ≤ 𝑥 < 5.5.3-40 |
𝑥
= Vulnerable software versions