CVE-2026-41530

LOW

Chitora Soft Lhaz - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Title source: rule
STIX 2.1

Description

The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation feature enabled, and a product user tries to extract an archive file which has a crafted file name, then the archived files may be extracted to an unexpected folder.

Scores

CVSS v3 3.3
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
Chitora soft/Lhaz 2.6.3 and earlier
Chitora soft/Lhaz+ 3.6.3 and earlier
Published May 12, 2026
Tracked Since May 12, 2026