Double Decoding of the Same Data in NukeViet - CVE-2026-94599

 

Double Decoding of the Same Data in NukeViet - CVE-2026-94599

Published: October 2, 2026


Vulnerability identifier: #VU153174
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-94599
CWE-ID: CWE-174
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in the origin of the NukeViet site.

The vulnerability exists due to double decoding of the same data in the news module search function when processing a crafted q parameter. A remote attacker can send a crafted link to a victim to execute arbitrary JavaScript in the origin of the NukeViet site.

User interaction is required to open the crafted link.


Affected software

NukeViet

How to mitigate CVE-2026-94599

Install security update from vendor's website.

NukeViet - addressed in versions 4.5.13, 4.6.02

External References

Related Security Bulletins