XML External Entity injection in NukeViet - #VU139337
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper restriction of XML external entity reference in vendor/vinades/nukeviet/Files/Upload.php when parsing uploaded SVG files. A remote user can upload a crafted SVG file with an external entity reference to disclose sensitive information.
This issue affects PHP versions earlier than 8.0.