Description
The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation feature enabled, and a product user tries to extract an archive file which has a crafted file name, then the archived files may be extracted to an unexpected folder.
Published: 2026-05-12
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Chitora
Chitora lhaz
Vendors & Products Chitora
Chitora lhaz

Tue, 12 May 2026 07:15:00 +0000

Type Values Removed Values Added
Title Automatic Folder Creation Path Traversal in Lhaz and Lhaz+

Tue, 12 May 2026 05:30:00 +0000

Type Values Removed Values Added
Description The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation feature enabled, and a product user tries to extract an archive file which has a crafted file name, then the archived files may be extracted to an unexpected folder.
Weaknesses CWE-22
References
Metrics cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-05-12T13:18:08.982Z

Reserved: 2026-04-21T00:48:03.452Z

Link: CVE-2026-41530

cve-icon Vulnrichment

Updated: 2026-05-12T13:18:03.500Z

cve-icon NVD

Status : Deferred

Published: 2026-05-12T06:16:09.073

Modified: 2026-05-12T15:10:27.993

Link: CVE-2026-41530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T08:45:11Z

Weaknesses