A vulnerability described as critical has been identified in Develar app-builder up to 4.2.0. This impacts the function zipx.Unzip of the component Extraction Routine. The manipulation results in path traversal.

This vulnerability was named CVE-2026-13723. The attack may be performed from remote. There is no available exploit.