{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kodexplorer--4.55/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kodexplorer:kodexplorer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104081"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KodExplorer (\u003c 4.55)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","web-application"],"_cs_type":"advisory","_cs_vendors":["KodExplorer"],"content_html":"\u003cp\u003eKodExplorer versions prior to 4.55 are susceptible to a path traversal vulnerability located within the unzip_pre_name() function in app/function/helper.function.php. The vulnerability arises from an insufficient sanitization implementation using a single non-recursive str_replace() call, which can be bypassed by attackers using crafted path sequences such as \u0026quot;....//\u0026quot;. Furthermore, the application's implementation of the PclZip library in KodArchive.class.php fails to utilize the necessary PCLZIP_OPT_EXTRACT_DIR_RESTRICTION, allowing the traversal sequences to escape the intended directory boundaries. Authenticated attackers can leverage this flaw by uploading a maliciously crafted ZIP archive containing traversal filenames. This enables the overwriting of critical core assets, specifically JavaScript files, facilitating stored XSS. By targeting administrative sessions, an attacker can gain unauthorized access to the application, subsequently enabling the upload of arbitrary PHP files and achieving remote code execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target KodExplorer instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a ZIP archive containing files with traversal path names (e.g., \u0026quot;....//....//index.php\u0026quot;).\u003c/li\u003e\n\u003cli\u003eAttacker uploads the malicious ZIP archive via the application's file management interface.\u003c/li\u003e\n\u003cli\u003eThe application processes the archive using the vulnerable unzip_pre_name() function.\u003c/li\u003e\n\u003cli\u003eThe traversal bypass occurs, and the PclZip library executes the file extraction without directory restrictions.\u003c/li\u003e\n\u003cli\u003eThe attacker overwrites a core JavaScript asset file with malicious XSS payloads.\u003c/li\u003e\n\u003cli\u003eA victim administrator accesses the compromised JavaScript asset, triggering the stored XSS.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the hijacked administrator session to upload a webshell for remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to gain administrative control over the KodExplorer instance. By overwriting core files and achieving remote code execution, attackers can gain full control over the underlying server environment, potentially leading to data exfiltration, service disruption, and lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate KodExplorer to version 4.55 or later immediately to patch the vulnerable unzip_pre_name() function.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests to file upload endpoints originating from authenticated user accounts.\u003c/li\u003e\n\u003cli\u003eAudit file system integrity for modifications to core application JavaScript files located in the web root.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T15:30:46Z","date_published":"2026-10-09T15:30:46Z","id":"https://feed.craftedsignal.io/briefs/2026-10-kodexplorer-path-traversal/","summary":"KodExplorer before version 4.55 contains a path traversal vulnerability in the unzip_pre_name() function that allows authenticated attackers to perform arbitrary file overwrites and achieve remote code execution.","title":"Path Traversal Vulnerability in KodExplorer (CVE-2026-104081)","url":"https://feed.craftedsignal.io/briefs/2026-10-kodexplorer-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - KodExplorer (\u003c 4.55)","version":"https://jsonfeed.org/version/1.1"}