Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android File Picker Path Traversal Allowing Creation of Files Outside the Intended Directory | |
| Weaknesses | CWE-22 |
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from ContentResolver.query() directly in file path construction without sanitization. A malicious Android app with a crafted ContentProvider can return a filename containing ../ sequences, causing the plugin to create arbitrary files and directories outside the intended cache directory within the victim app's internal storage. Existing files are not overwritten due to an existence check. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T19:27:21.385Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38093
Updated: 2026-08-28T19:27:12.105Z
Status : Received
Published: 2026-08-28T16:17:46.793
Modified: 2026-08-28T20:17:27.200
Link: CVE-2026-38093
No data.
OpenCVE Enrichment
Updated: 2026-08-28T17:30:08Z