Executive brief
Mogu Blog is a popular blogging platform with file management capabilities. A path traversal vulnerability in its ZIP extraction feature allows remote attackers to write arbitrary files to the server, potentially leading to code execution, data corruption, or complete system compromise.
Technical details
The vulnerability is a classic zip slip (path traversal) flaw in the FileOperation.unzip() function accessed via the /networkDisk/unzipFile endpoint. By crafting a malicious ZIP archive with path traversal sequences (e.g., "../../../") in filenames, an attacker can write files outside the intended extraction directory. The attack requires network access and does not require authentication. An attacker can achieve arbitrary file write on the server, potentially leading to remote code execution. The vendor was notified early but did not respond or provide a patch.
Affected products
- moxi159753 Mogu Blog v2 up to 5.2
Timeline
- 2025-12-01: disclosed: Publicly disclosed on GitHub
- 2025-12-01: advisory: CVE-2025-13816 published