PYSEC-2026-2856

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/openviking/PYSEC-2026-2856.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-2856
Aliases
Published
2026-07-13T14:36:40Z
Modified
2026-07-13T16:32:34Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenViking contains a Path Traversal vulnerability
Details

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.

References

Affected packages

PyPI / openviking

Package

Name
openviking
View open source insights on deps.dev
Purl
pkg:pypi/openviking

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.2.1

Affected versions

0.*
0.1.17
0.1.18
0.2.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/openviking/PYSEC-2026-2856.yaml"