Double Decoding of the Same Data in NukeViet - CVE-2026-94599
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the origin of the NukeViet site.
The vulnerability exists due to double decoding of the same data in the news module search function when processing a crafted q parameter. A remote attacker can send a crafted link to a victim to execute arbitrary JavaScript in the origin of the NukeViet site.
User interaction is required to open the crafted link.