CVE-2026-28518 Details
Description
OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.
A path traversal vulnerability has been identified in OpenViking versions through 0.2.1, within the .ovpack import process. This vulnerability allows attackers to write files outside the designated import directory by crafting malicious ZIP archives that include traversal sequences, absolute paths, or drive prefixes in the member names. Such archives can overwrite or create arbitrary files with the privileges of the importing process.
Users are advised to update to OpenViking version 0.2.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/volcengine/OpenViking/issues/342 | CISA-ADP | Issue Tracking |
| https://github.com/volcengine/OpenViking/commit/46b3e76e28b9b3eee73693720c9ec48820228b72 | [email protected] | Patch |
| https://github.com/volcengine/OpenViking/issues/342 | [email protected] | Issue Tracking |
| https://www.vulncheck.com/advisories/openviking-ovpack-import-zip-slip-path-traversal | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| volcengine openviking | < 0.2.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | New CVE Received | [email protected] |