Cryptographic Vulnerability in Meesho Online Shopping App for Android
CVE-2026-5682
Key Information:
- Vendor
Meesho
- Status
- Vendor
- CVE Published:
- 6 April 2026
Badges
What is CVE-2026-5682?
The Meesho Online Shopping App for Android, specifically the component com.meesho.supply, has a vulnerability involving an unknown function within the /api/endpoint. This issue allows for the manipulation of cryptographic algorithms, potentially leading to insecure data handling. Although the complexity of executing this attack is high, its disclosure poses a risk to users, as attackers may exploit this vulnerability remotely. Users should be aware of the potential for compromised security due to improper encryption techniques utilized in the affected version.
Affected Version(s)
Online Shopping App 27.0
Online Shopping App 27.1
Online Shopping App 27.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
