CVE-2025-55911 describes a remote code execution vulnerability in Clip Bucket v.5.5.2 Build#90, specifically within the file_downloader.php script via the 'file' parameter. This medium-severity vulnerability (CVSS 6.5) allows an unauthenticated attacker to execute arbitrary code with low attack complexity, potentially leading to limited confidentiality and integrity impacts. While no active exploitation or Metasploit/Nuclei modules are reported, an ExploitDB entry (EDB-52434) exists, indicating public exploit code for a Server-Side Request Forgery (SSRF) related to this issue, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5.2-90CPE matchmatch criteria | cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.