CVE-2026-28518

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows attackers to overwrite or create files on the server by tricking the system into importing malicious ZIP files that contain special path sequences. It affects OpenViking versions 0.2.1 and earlier, and requires the attacker to have access to upload these specially crafted ZIP archives.

Technical Description

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.

CVSS Vector Analysis

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged

Vector String

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$3,947($1K-$5K)
Vendor Response
Grade APatched in 0 days

Quick Information

Published

Mar 3, 2026

about 1 month ago

Last Modified

Mar 3, 2026

about 1 month ago