Path traversal in NukeViet - #VU139339

 

Path traversal in NukeViet - #VU139339

Published: July 24, 2026


Vulnerability identifier: #VU139339
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write files outside the expected extension directory.

The vulnerability exists due to path traversal in the extension package upload and installation flow when processing crafted ZIP entry paths during archive extraction. A remote privileged user can upload a specially crafted ZIP archive to write files outside the expected extension directory.

Only instances with the extension upload and install feature enabled are vulnerable. In certain deployments, this may lead to code execution if the written files are interpreted by the server.


Affected software

NukeViet

Remediation

Install security update from vendor's website.

NukeViet - update to 4.5.09

External References

Related Security Bulletins