Description
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
Published: 2026-07-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal vulnerability has been identified in the GeoIP extension for Joomla distributed by regularlabs.com. The extension’s update process extracts ZIP archives containing the GeoIP database without validating file paths. An attacker who can supply a crafted archive during a database update can cause files to be written outside the intended directory, potentially allowing overwrite of existing files or creation of new files in arbitrary locations. If such files reside in a web‑executable location, this could enable execution of malicious code on the Joomla site.

Affected Systems

The flaw affects the GeoIP extension for Joomla produced by regularlabs.com. No specific version range is supplied in the CVE data, so administrators should verify the installed version against the vendor’s release notes to determine whether it is impacted.

Risk and Exploitability

The CVSS score of 9.8 signals a critical vulnerability. The EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves manipulating the extension’s update mechanism, such as by tampering with the update feed or delivering a malicious archive to the update system. Successful exploitation could lead to arbitrary file creation or overwrite, with potential impact on confidentiality, integrity, or availability of the Joomla installation.

Generated by OpenCVE AI on August 2, 2026 at 17:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the GeoIP extension version you have installed and upgrade to the latest release from regularlabs.com if a fix is included.
  • If no patch is available, disable the extension or its automated update feature until an update with mitigation is released.
  • Perform a file‑integrity audit of the Joomla installation, focusing on directories used by the GeoIP extension, to detect unauthorized or overwritten files that may indicate a prior exploitation attempt.

Generated by OpenCVE AI on August 2, 2026 at 17:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com geoip Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com geoip Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

Thu, 23 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
Title Joomla Extension - regularlabs.com - Zipslip in GeoIP extension
Weaknesses CWE-22
References

Subscriptions

Regularlabs.com Geoip Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-28T05:30:43.017Z

Reserved: 2026-07-22T07:06:47.089Z

Link: CVE-2026-65431

cve-icon Vulnrichment

Updated: 2026-07-27T16:40:32.687Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:52.723

Modified: 2026-07-27T17:16:39.360

Link: CVE-2026-65431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')