Get real-time updates on Telegram
CVE-2026-28518: openviking before 0.2.1 (exclusive); +1 more affected products
CVE-2026-28518. CVSS 3.1 base score 7.8 (HIGH, Vendor/CNA). EPSS 0.00191 (percentile 0.08011), scored 2026-10-06.
Affected technology
openviking · before 0.2.1 (exclusive)
volcengine
OpenViking · 0 through 0.2.1
Volcengine
Description’s affected range: versions 0.2.1 and prior, fixed in commit 46b3e76,
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · Active user interaction
What an attacker can do
Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges. Vendor/CNA’s CVSS 4.0 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-22
- CCR priority
- 31.2 /100 (P4)
- CVSS 3.1
- 7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.00191 · percentile 0.08048 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-28518.html