SCA: security update for github.com/0xJacky/Nginx-UI (GHSA-p8v3-89rh-jxc7)

high Tenable Cloud Security Plugin ID 474036

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0,
internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui
flags and permits symlinks targeting the live Nginx configuration path. An authenticated user who can
create and restore backups can craft a valid backup that places a symlink in the staging tree and then
writes a regular file through that link, even when both restore flags are false. This can persistently
inject configuration or cause denial of service when the modified files are later consumed. This issue is
fixed in version 2.5.0. (CVE-2026-107810)

Solution

Update the github.com/0xJacky/Nginx-UI library and its related packages to version 1.9.10-0.20260728074146-a467ed652591 or later.

See Also

https://github.com/advisories/GHSA-p8v3-89rh-jxc7

Plugin Details

Severity: High

ID: 474036

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2026-107810

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-107810