---
id: CVE-2025-65113
title: ClipBucket v5 is an open source video sharing platform
summary: >-
  ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2
  - #164, an authorization bypass vulnerability in the AJAX flagging system
  allows any unauthenticated user to flag any content (users, videos, photos,
  collecti…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-770
vendor: oxygenz
product: clipbucket
affected:
  - 'clipbucket >= 5.3, < 5.5.2-164'
patched:
  - clipbucket 5.5.2-164
published: '2025-11-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65113'
references:
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/commit/a83b807e592f85d98f1f156bd3cbb1ffcc230233
    label: security-advisories@github.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-9f8v-vph8-pq6q
    label: security-advisories@github.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-9f8v-vph8-pq6q
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00398
epssPercentile: 0.31777
ingestedAt: '2026-10-07T20:46:46.735Z'
---

## Overview

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows any unauthenticated user to flag any content (users, videos, photos, collections) on the platform. This can lead to mass flagging attacks, content disruption, and moderation system abuse. This issue has been patched in version 5.5.2 - #164.

## Affected

- `clipbucket >= 5.3, < 5.5.2-164`

## Remediation

Upgrade past the affected range:

- `clipbucket 5.5.2-164`
