Path Traversal Vulnerability in achorein expo-share-intent Android File Copy Routine
CVE-2026-78196

4.8MEDIUM

Key Information:

Vendor

Achorein

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78196?

A security flaw present in the expo-share-intent component affects its getDataColumn function, specifically within the ExpoShareIntentModule.kt file. This vulnerability allows for a potential path traversal attack by manipulating the _display_name argument, leading to unauthorized access within the file system. Attackers must execute this exploit locally, emphasizing the need for users to upgrade to version 8.0.1 or later to patch this vulnerability effectively.

Affected Version(s)

expo-share-intent 8.0

expo-share-intent 8.0.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Actuator (VulDB User)
.