GHSA-rpqr-j937-6qr9

Suggest an improvement
Source
https://github.com/advisories/GHSA-rpqr-j937-6qr9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rpqr-j937-6qr9/GHSA-rpqr-j937-6qr9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rpqr-j937-6qr9
Aliases
Published
2026-03-03T15:31:41Z
Modified
2026-09-10T03:50:40Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenViking contains a Path Traversal vulnerability
Details

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-04T20:25:40Z",
    "nvd_published_at":  "2026-03-03T15:16:20Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / openviking

Package

Name
openviking
View open source insights on deps.dev
Purl
pkg:pypi/openviking

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rpqr-j937-6qr9/GHSA-rpqr-j937-6qr9.json"