Path Traversal Vulnerability in Ne-Lexa php-zip ZIP Handler
CVE-2026-16767
Key Information:
Badges
What is CVE-2026-16767?
A vulnerability has been identified in Ne-Lexa's php-zip library versions up to 4.0.2. It occurs within the ZipFile::extractTo function located in src/ZipFile.php, where inadequate validation of the entryName argument allows for malicious path traversal attacks. This vulnerability can be exploited remotely, enabling attackers to access unauthorized files on the server. The issue was reported to the project maintainers, but no response has been documented to date. Users of affected versions are advised to take preventive measures.
Affected Version(s)
php-zip 4.0.0
php-zip 4.0.1
php-zip 4.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
