Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. nukeviet/nukeviet
  4. ›
  5. CVE-2026-54065

CVE-2026-54065: NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

July 13, 2026

Path Traversal to Arbitrary File Deletion in the Edit Comment admin function. An authenticated administrator can delete arbitrary files within the application root (e.g., config.php) by injecting a crafted attach parameter, rendering the application inoperable.

References

  • github.com/advisories/GHSA-c9xg-64p9-f2jj
  • github.com/nukeviet/nukeviet/security/advisories/GHSA-c9xg-64p9-f2jj
  • nvd.nist.gov/vuln/detail/CVE-2026-54065

Code Behaviors & Features

Detect and mitigate CVE-2026-54065 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.6.0

Fixed versions

  • 4.6.0

Solution

Upgrade to version 4.6.0 or above.

Impact 8.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

packagist/nukeviet/nukeviet/CVE-2026-54065.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 19 Aug 2026 12:28:10 +0000.