CVE-2026-41203Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. This issue has been patched in version 0.31.5.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-07)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-23: 1Mentions · 2026-05-07: 3Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-07: 204-2305-07
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-05-073
Disclosure2General1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-41203 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.… https://www.cve.org/CVERecord?id=CVE-2026-41203

    Post summary

    The statement only identifies a CVE ID for a CodeIgniter CMS skeleton and links to its record, without any further detail on exploitation, patches, or technical aspects.

    00000102
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41203 📊 Severity: 9.4 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41203 #CVE-2026-41203 #CVE #Critical #CyberSecurity #InfoSec https://t.co/uKudNw0qSJ

    Post summary

    The post announces a new CVE with a high severity rating, but it offers only limited technical details without evidence of a PoC, exploit code, activity, or remediation steps.

    0000036
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41203 Arbitrary File Write and Remote Code Execution in CI4MS Theme Upload via Zip Slip https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41203

    Post summary

    CVE-2026-41203 enables arbitrary file write and remote code execution through a zip slip flaw in CI4MS Theme uploads, with technical details supplied but no PoC, exploit code, or patch referenced.

    0000045
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical Zip Slip vulnerability (CVE-2026-41203) affects CI4MS Theme's upload function, enabling remote code execution. Monitor for patch availability. #ZipSlip #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-41203-ci4ms-theme-zip-slip-rce

    Post summary

    The tweet announces the disclosure of CVE‑2026‑41203, a critical Zip Slip flaw in CI4MS Theme that facilitates remote code execution, and urges readers to stay alert for an upcoming patch, though it offers no PoC, exploit details, or active exploitation evidence.

    0000073
    12 followersView on X

Explore more