CVE-2026-28518Disclosure(volcengine / openviking)

LOWCVSS 8.4 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch volcengine openviking systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openviking

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
openviking

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-03: 4Patch / Workaround · 2026-03-03: 2Technical Details · 2026-03-03: 403-03
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28518 Path Traversal in OpenViking 0.2.1 Enabling Arbitrary File Write via ZIP Import https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28518

    Post summary

    The text announces a path traversal vulnerability in OpenViking 0.2.1 that allows arbitrary file writes via ZIP import, with no mention of PoC, exploit, patch, or active exploitation.

    0001075
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28518 - OpenViking .ovpack Import ZIP Slip Path Traversal Intel Report: https://ift.tt/lu5coYN

    Post summary

    A threat alert identifies CVE-2026-28518 as a ZIP Slip path traversal flaw in OpenViking’s .ovpack import, with an Intel report link provided.

    0000058
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28518 OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write fil… https://www.cve.org/CVERecord?id=CVE-2026-28518 ----- Traducción: CVE-2026-28518 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑28518, a path traversal flaw in OpenViking, provides technical details, and notes the fix in commit 46b3e76, but does not mention exploits or active attacks.

    0000044
    55 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-28518 OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write fil… https://www.cve.org/CVERecord?id=CVE-2026-28518

    Post summary

    CVE-2026-28518 is a path traversal flaw in OpenViking 0.2.1 and earlier, fixed in commit 46b3e76, enabling attackers to write files via the .ovpack import handling.

    00000171
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvolcengineopenviking---

Explore more