CVE-2026-28518 PUBLISHED

OpenViking .ovpack Import ZIP Slip Path Traversal

Assigner: VulnCheck
Reserved: 27.02.2026 Published: 03.03.2026 Updated: 03.03.2026

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Volcengine
Product OpenViking
Versions Default: unaffected
  • affected from 0 to 0.2.1 (incl.)
  • Version commit 46b3e76 is unaffected

Credits

  • Chia Min Jun Lennon finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE