{"id":"GHSA-c9xg-64p9-f2jj","summary":"NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function","details":"## Summary\n\nPath Traversal to Arbitrary File Deletion in the Edit Comment admin function. An authenticated administrator can delete arbitrary files within the application root (e.g., `config.php`) by injecting a crafted `attach` parameter, rendering the application inoperable.\n\n## Affected Component\n\n`modules/comment/admin/edit.php`\n\n## Root Cause\n\nIn the vulnerable version, the `attach` parameter received via HTTP POST was not validated before being processed:\n\n```php\n// Vulnerable code (before fix)\n$attach = $nv_Request-\u003eget_string('attach', 'post', '', true);\nif (!empty($attach)) {\n    $attach = substr($attach, strlen(NV_BASE_SITEURL . NV_UPLOADS_DIR . '/' . $module_upload . '/'));\n}\n```\n\n`substr()` strips the first N characters (equal to the length of the upload URL prefix, e.g. 26 chars for `/nukeviet/uploads/comment/`). By padding the payload with exactly 26 arbitrary characters followed by a path traversal sequence, an attacker can store `../../\u003ctarget\u003e` directly into the database.\n\nWhen the comment is subsequently deleted, `del.php` reads `attach` from the database and calls:\n\n```php\nnv_deletefile(NV_UPLOADS_REAL_DIR . '/' . $module_upload . '/' . $row['attach']);\n```\n\n`nv_deletefile()` resolves the path via `realpath()` and only verifies the result is within `NV_ROOTDIR` — it does **not** restrict deletion to the uploads directory — allowing deletion of any file in the installation root.\n\n## Steps to Reproduce\n\n1. Log in as an administrator and navigate to **Admin → Comment Management**.\n2. Select any comment and open the Edit form.\n3. Intercept the POST request and set the `attach` parameter to:\n\n```\naaaaaaaaaaaaaaaaaaaaaaaaaa../../config.php\n```\n\n*(26 padding characters + traversal path)*\n\n4. Submit the request. The value `../../config.php` is now stored in the database.\n5. Delete the comment. `config.php` is deleted from the application root.\n6. The application immediately redirects to the install wizard, confirming the file has been removed.\n\n## Impact\n\n- Any file readable by the web server process within `NV_ROOTDIR` can be permanently deleted.\n- Deleting `config.php` causes a full application outage and exposes the install wizard.\n\n## Severity\n\n**CVSS v3.1 Base Score: 8.7 (High)**\n\n```\nCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H\n```\n\n| Metric | Value |\n|--------|-------|\n| Attack Vector | Network |\n| Attack Complexity | Low |\n| Privileges Required | High (Admin required) |\n| User Interaction | None |\n| Scope | Changed |\n| Confidentiality | None |\n| Integrity | High |\n| Availability | High |\n\n## Fix\n\nAdded `nv_is_file()` validation before processing the `attach` value. This function uses `realpath()` and a regex check to ensure the file resolves to a path within the intended upload directory, rejecting any traversal attempts.\n\n```php\n// Fixed code\n$attach = $nv_Request-\u003eget_string('attach', 'post', '');\nif (!empty($attach) and nv_is_file($attach, NV_UPLOADS_DIR . '/' . $module_upload)) {\n    $attach = substr($attach, strlen(NV_BASE_SITEURL . NV_UPLOADS_DIR . '/' . $module_upload . '/'));\n} else {\n    $attach = '';\n}\n```","aliases":["CVE-2026-54065"],"modified":"2026-07-13T18:11:45.808032Z","published":"2026-07-13T17:55:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-13T17:55:48Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/nukeviet/nukeviet/security/advisories/GHSA-c9xg-64p9-f2jj"},{"type":"PACKAGE","url":"https://github.com/nukeviet/nukeviet"}],"affected":[{"package":{"name":"nukeviet/nukeviet","ecosystem":"Packagist","purl":"pkg:composer/nukeviet/nukeviet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.00"}]}],"versions":["4.0.24","4.4.01"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-c9xg-64p9-f2jj/GHSA-c9xg-64p9-f2jj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"}]}