---
id: CVE-2025-11016
title: A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09
summary: >-
  A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09.
  The affected element is the function fileOut of the file
  app/controller/explorer/index.class.php. Such manipulation of the argument
  path leads to path traversa…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
published: '2025-09-26'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11016'
references:
  - url: 'https://github.com/August829/YU1/issues/3'
    label: cna@vuldb.com
  - url: 'https://github.com/August829/YU1/issues/3#issue-3416620392'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.325959'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.325959'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.654367'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00461
epssPercentile: 0.37964
ingestedAt: '2026-10-09T12:53:27.564Z'
---

## Overview

A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation of the argument path leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
