Path Traversal Vulnerability in Lippu Docx Reader Office Viewer App on Android
CVE-2026-108544

5.3MEDIUM

Key Information:

Vendor

Lippu

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108544?

A vulnerability exists in the Lippu Docx Reader Office Viewer App, specifically affecting versions up to 1.4.5 on Android devices. This vulnerability is triggered through improper handling of the argument _display_name in the function word.office.docxviewer.document.docx.reader.ViewTxt, allowing attackers to exploit path traversal. Such an exploit can enable unauthorized access to sensitive files on the device, potentially permitting remote attacks on users.

Affected Version(s)

Docx Reader Office Viewer App 1.4.0

Docx Reader Office Viewer App 1.4.1

Docx Reader Office Viewer App 1.4.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Secsys-FDU (VulDB User)
.