Path traversal in nginx-ui - #VU142580
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to write files outside the intended backup storage directory.
The vulnerability exists due to path traversal in auto-backup filename generation when handling a user-controlled auto-backup name. A remote user can create or modify an auto-backup task with crafted path traversal sequences in the name to write files outside the intended backup storage directory.
For encrypted configuration backups, the adjacent .key file may also be written outside the intended storage directory with the application process privileges.