Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78196— achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt getDataColumn path traversal

Quick assessment

Affected
achorein expo-share-intent
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 achorein expo-share-intent 8.0.0 及更早版本中发现了一个安全漏洞。该漏洞影响 Android 文件复制例程(Android File Copy Routine)组件中的 ExpoShareIntentModule.kt 文件的 getDataColumn 函数。通过对参数 _display_name 的操作可导致路径遍历(path traversal)。此攻击需要本地访问权限。升级至 8.0.1 版本可缓解此问题。相关补丁标识为 c6900b1ed06fcc3ca4b096513

CVSS 4.4 · Medium

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78196

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt getDataColumn path traversal
Source: CVE Program / CVE List V5
Vulnerability Description
A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
achorein expo-share-intent 8.0 cpe:2.3:a:achorein:expo-share-intent:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-78196

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78196

登录查看更多情报信息。

Patches & Fixes for CVE-2026-78196 (3)

Vendor Advisories for CVE-2026-78196 (2)

Exploits & Public PoCs for CVE-2026-78196 (1)

Other References for CVE-2026-78196 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-78196

No comments yet


Leave a comment