No CVE yet, one has been requested.
Upgrade to 0.072 of ZNC, fixes security issue in bug 513152
An users data directory traversal flaw was found in the way ZNC used to handle file upload requests via Direct Client Connection (DCC) /dcc SEND messages. A remote IRC user could issue a /dcc SEND message with a specially-crafted content (file to upload), which once accepted by a local, unsuspecting ZNC user, would overwrite relevant files in the users/<user>/downloads data directory.
Please login to add feedback.
This update has been pushed to stable