A vulnerability classified as critical has been found in jahlives openssl_encrypt up to 1.3.x. This impacts the function _is_safe_path. Performing a manipulation of the argument plugin_id results in path traversal.

This vulnerability is reported as CVE-2026-74884. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.