CVE-2026-54065: NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
Path Traversal to Arbitrary File Deletion in the Edit Comment admin function. An authenticated administrator can delete arbitrary files within the application root (e.g., config.php) by injecting a crafted attach parameter, rendering the application inoperable.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54065 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →