A vulnerability described as critical has been identified in Develar app-builder up to 4.2.0. This impacts the function
zipx.Unzip of the component Extraction Routine. The manipulation results in path traversal.
This vulnerability was named CVE-2026-13723. The attack may be performed from remote. There is no available exploit.