Junglewise Threat Intelligence

CVE-2025-13816: Mogu Blog v2 path traversal in ZIP file handler

CVE-2025-13816 · Severity: medium · CVSS 6.3 · Published 2025-12-01

Technologies: Mogublog Project Mogublog. Vendors: Moxi159753, Mogublog Project.

Executive brief

Mogu Blog is a popular blogging platform with file management capabilities. A path traversal vulnerability in its ZIP extraction feature allows remote attackers to write arbitrary files to the server, potentially leading to code execution, data corruption, or complete system compromise.

Technical details

The vulnerability is a classic zip slip (path traversal) flaw in the FileOperation.unzip() function accessed via the /networkDisk/unzipFile endpoint. By crafting a malicious ZIP archive with path traversal sequences (e.g., "../../../") in filenames, an attacker can write files outside the intended extraction directory. The attack requires network access and does not require authentication. An attacker can achieve arbitrary file write on the server, potentially leading to remote code execution. The vendor was notified early but did not respond or provide a patch.

Affected products

  • moxi159753 Mogu Blog v2 up to 5.2

Timeline

  • 2025-12-01: disclosed: Publicly disclosed on GitHub
  • 2025-12-01: advisory: CVE-2025-13816 published

References

Related threats