Path traversal in NukeViet - #VU139339
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to write files outside the expected extension directory.
The vulnerability exists due to path traversal in the extension package upload and installation flow when processing crafted ZIP entry paths during archive extraction. A remote privileged user can upload a specially crafted ZIP archive to write files outside the expected extension directory.
Only instances with the extension upload and install feature enabled are vulnerable. In certain deployments, this may lead to code execution if the written files are interpreted by the server.