Incomplete List of Disallowed Inputs in NukeViet - #VU153179

 

Incomplete List of Disallowed Inputs in NukeViet - #VU153179

Published: October 2, 2026


Vulnerability identifier: #VU153179
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause the server to issue requests to internal hosts and disclose limited internal binary files.

The vulnerability exists due to incomplete validation of IPv4-mapped IPv6 addresses in the URL-based file import feature when submitting a hostname whose AAAA record resolves to a mapped internal address. A remote privileged user can submit a crafted hostname to cause the server to issue requests to internal hosts and disclose limited internal binary files.

Exploitation reaches internal IPv4 services only on operating systems that map IPv4-mapped IPv6 addresses to IPv4 endpoints; persisted responses must be recognized as allowed binary file types.


Affected software

NukeViet

Remediation

Install security update from vendor's website.

NukeViet - update to 4.6.02

External References

Related Security Bulletins