CVE-2026-78196 PUBLISHED

achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt getDataColumn path traversal

Assigner: VulDB
Reserved: 23.08.2026 Published: 24.08.2026 Updated: 24.08.2026

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 4.8

Product Status

Vendor achorein
Product expo-share-intent
Versions
  • Version 8.0 is affected
  • Version 8.0.1 is unaffected

Credits

  • Actuator (VulDB User) reporter

References

Problem Types

  • Path Traversal CWE