Path Traversal Vulnerability in KodExplorer by Kalcaddle
CVE-2026-104081

7.2HIGH

Key Information:

Vendor

Kalcaddle

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104081?

KodExplorer prior to version 4.55 contains a vulnerability that allows an authenticated attacker to exploit a path traversal flaw in the unzip_pre_name() function. This flaw can be triggered by uploading a specially crafted ZIP archive containing traversal sequences, such as '....//', which bypasses the inadequate sanitization provided by str_replace(). As a result, it can compromise critical files, leading to stored XSS and enabling the attacker to gain control over admin accounts, eventually allowing for unrestricted PHP file uploads and remote code execution.

Affected Version(s)

KodExplorer 0 < 4.55

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Ali Sotvoldiyev
.