A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal | |
| First Time appeared |
Ne-lexa
Ne-lexa php-zip |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ne-lexa:php-zip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ne-lexa
Ne-lexa php-zip |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-07-23T22:15:11.686Z
Reserved: 2026-07-23T14:25:29.169Z
Link: CVE-2026-16767
No data.
No data.
No data.
OpenCVE Enrichment
No data.