Interpretation Conflict in NukeViet - CVE-2026-94567
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in the site's origin.
The vulnerability exists due to an interpretation conflict in the SVG sanitizer in Files/Upload.php when processing uploaded SVG files. A remote attacker can upload a specially crafted SVG file containing a script hidden in an internal DTD entity to execute arbitrary script in the site's origin.
User interaction is required to open the uploaded SVG file in a browser.