CVE-2026-104081: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in kalcaddle KodExplorer
Description
KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload.
CVSS v4.0
Score 7.2high
Affected software
kalcaddle
KodExplorer
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104081 is a path traversal vulnerability in KodExplorer prior to version 4.55. The vulnerability arises from insufficient sanitization in the unzip_pre_name() function, which uses a single non-recursive str_replace() pass that can be bypassed with crafted filenames such as "....//". Additionally, the PclZip extract() call in KodArchive.class.php does not use the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option, allowing extraction outside intended directories. An authenticated attacker can upload a malicious ZIP archive containing traversal sequences to overwrite arbitrary files, including core JavaScript assets. This can lead to stored XSS, enabling admin account takeover and remote code execution via unrestricted PHP file upload.
Potential Impact
An attacker with authentication can exploit this vulnerability to overwrite arbitrary files on the server, including critical JavaScript assets. This enables stored XSS attacks that can compromise administrator accounts. Following account takeover, the attacker can achieve remote code execution by uploading PHP files without restriction. The CVSS 4.0 score is 7.2 (high severity), reflecting network attack vector, low attack complexity, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions to prevent uploading ZIP archives or untrusted files. Monitor for suspicious file changes and consider disabling ZIP extraction features if possible. Follow vendor advisories closely for updates and apply official patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-01T18:02:50.084Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac8fb5f2cdf04f6565ebf27
Added to database: 10/09/2026, 14:34:07 UTC
Last enriched: 10/09/2026, 14:48:27 UTC
Last updated: 10/09/2026, 18:57:31 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.