XML External Entity injection in NukeViet - #VU139337

 

XML External Entity injection in NukeViet - #VU139337

Published: July 24, 2026


Vulnerability identifier: #VU139337
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper restriction of XML external entity reference in vendor/vinades/nukeviet/Files/Upload.php when parsing uploaded SVG files. A remote user can upload a crafted SVG file with an external entity reference to disclose sensitive information.

This issue affects PHP versions earlier than 8.0.


Affected software

NukeViet

Remediation

Install security update from vendor's website.

NukeViet - update to 4.5.09

External References

Related Security Bulletins