CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-28518: openviking before 0.2.1 (exclusive); +1 more affected products

CVE-2026-28518. CVSS 3.1 base score 7.8 (HIGH, Vendor/CNA). EPSS 0.00191 (percentile 0.08011), scored 2026-10-06.

Affected technology

openviking · before 0.2.1 (exclusive)
volcengine

OpenViking · 0 through 0.2.1
Volcengine

Description’s affected range: versions 0.2.1 and prior, fixed in commit 46b3e76,

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · Active user interaction

What an attacker can do

Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges. Vendor/CNA’s CVSS 4.0 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-22
CCR priority
31.2 /100 (P4)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00191 · percentile 0.08048 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-28518.html