<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kodexplorer:kodexplorer:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akodexplorerkodexplorer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 15:30:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akodexplorerkodexplorer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in KodExplorer (CVE-2026-104081)</title><link>https://feed.craftedsignal.io/briefs/2026-10-kodexplorer-path-traversal/</link><pubDate>Fri, 09 Oct 2026 15:30:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-kodexplorer-path-traversal/</guid><description>KodExplorer before version 4.55 contains a path traversal vulnerability in the unzip_pre_name() function that allows authenticated attackers to perform arbitrary file overwrites and achieve remote code execution.</description><content:encoded><![CDATA[<p>KodExplorer versions prior to 4.55 are susceptible to a path traversal vulnerability located within the unzip_pre_name() function in app/function/helper.function.php. The vulnerability arises from an insufficient sanitization implementation using a single non-recursive str_replace() call, which can be bypassed by attackers using crafted path sequences such as &quot;....//&quot;. Furthermore, the application's implementation of the PclZip library in KodArchive.class.php fails to utilize the necessary PCLZIP_OPT_EXTRACT_DIR_RESTRICTION, allowing the traversal sequences to escape the intended directory boundaries. Authenticated attackers can leverage this flaw by uploading a maliciously crafted ZIP archive containing traversal filenames. This enables the overwriting of critical core assets, specifically JavaScript files, facilitating stored XSS. By targeting administrative sessions, an attacker can gain unauthorized access to the application, subsequently enabling the upload of arbitrary PHP files and achieving remote code execution.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates to the target KodExplorer instance.</li>
<li>Attacker crafts a ZIP archive containing files with traversal path names (e.g., &quot;....//....//index.php&quot;).</li>
<li>Attacker uploads the malicious ZIP archive via the application's file management interface.</li>
<li>The application processes the archive using the vulnerable unzip_pre_name() function.</li>
<li>The traversal bypass occurs, and the PclZip library executes the file extraction without directory restrictions.</li>
<li>The attacker overwrites a core JavaScript asset file with malicious XSS payloads.</li>
<li>A victim administrator accesses the compromised JavaScript asset, triggering the stored XSS.</li>
<li>Attacker leverages the hijacked administrator session to upload a webshell for remote code execution.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to gain administrative control over the KodExplorer instance. By overwriting core files and achieving remote code execution, attackers can gain full control over the underlying server environment, potentially leading to data exfiltration, service disruption, and lateral movement within the network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Update KodExplorer to version 4.55 or later immediately to patch the vulnerable unzip_pre_name() function.</li>
<li>Review web server access logs for anomalous POST requests to file upload endpoints originating from authenticated user accounts.</li>
<li>Audit file system integrity for modifications to core application JavaScript files located in the web root.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>path-traversal</category><category>web-application</category></item></channel></rss>