Junglewise Threat Intelligence

CVE-2026-65431: Regular Labs GeoIP extension for Joomla path traversal in database updates

CVE-2026-65431 · Severity: info · Published 2026-07-23

Technologies: Regular Labs GeoIP. Vendors: Regular Labs.

Executive brief

The Regular Labs GeoIP extension for Joomla, which provides geolocation services for websites, contains a security flaw in how it handles database updates. An attacker could potentially provide a malicious update file that places files in unauthorized locations on the web server. This could lead to the corruption of website data or the execution of unauthorized code, compromising the site's integrity.

Technical details

A path traversal vulnerability (CWE-22) exists in the Regular Labs GeoIP extension for Joomla versions 1.0.0 through 6.3.8. The issue stems from the broad extraction of Geo IP database update archives without sufficient validation of the file paths contained within the archive. An attacker who can influence the source or content of the database update archive could potentially write arbitrary files to the server's filesystem. This could lead to remote code execution if the attacker is able to overwrite executable files or place new scripts in web-accessible directories.

Affected products

  • Regular Labs GeoIP extension for Joomla 1.0.0 through 6.3.8

Timeline

  • 2026-07-23: disclosed: CVE-2026-65431 published by the Joomla! Project.

References

Related threats