CVE-2026-78196

Source
https://cve.org/CVERecord?id=CVE-2026-78196
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78196.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78196
Published
2026-08-24T04:45:10.579Z
Modified
2026-08-28T11:30:43.383952227Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt getDataColumn path traversal
Details

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument displayname results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78196.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/achorein/expo-share-intent

Affected ranges

Type
GIT
Repo
https://github.com/achorein/expo-share-intent
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "8.0"
        },
        {
            "last_affected": "8.0"
        }
    ]
}

Affected versions

8.*
8.0
v8.*
v8.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78196.json"