CVE-2026-104081: KodExplorer < 4.55 Path Traversal via unzip_pre_name() ZIP Extraction
KodExplorer before 4.55 contains a path traversal vulnerability in the unzipprename() function within app/function/helper.function.php, where a single non-recursive strreplace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIPOPTEXTRACTDIRRESTRICTION option. Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
KodExplorerto a version that resolves this vulnerability.Fixed in 4.55
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated KodExplorer account and the ability to upload a crafted ZIP archive. No user interaction is required for the archive extraction step.
What is the practical impact of successful exploitation?
A crafted archive can overwrite arbitrary files, including core JavaScript assets. This can enable stored XSS, admin account takeover, and then remote code execution through unrestricted PHP file upload.
Are versions 4.55 and later affected?
The issue is reported in KodExplorer versions before 4.55. Updating to version 4.55 or later addresses the affected version range described here.
What can be done if upgrading is not immediately possible?
Restrict ZIP upload and extraction capability to only fully trusted accounts, since exploitation requires an authenticated user to upload a malicious archive. Monitor uploaded archives and extracted file paths for traversal-style names such as "....//".