Path Traversal Vulnerability in KodExplorer by Kalcaddle
CVE-2026-104081
7.2HIGH
What is CVE-2026-104081?
KodExplorer prior to version 4.55 contains a vulnerability that allows an authenticated attacker to exploit a path traversal flaw in the unzip_pre_name() function. This flaw can be triggered by uploading a specially crafted ZIP archive containing traversal sequences, such as '....//', which bypasses the inadequate sanitization provided by str_replace(). As a result, it can compromise critical files, leading to stored XSS and enabling the attacker to gain control over admin accounts, eventually allowing for unrestricted PHP file uploads and remote code execution.
Affected Version(s)
KodExplorer 0 < 4.55
