PT-2026-31464 · Abrignoni · Valeapp
Published
2026-04-08
·
Updated
2026-04-08
·
CVE-2026-40027
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ Vault.py artifact parser that uses attacker-controlled file name from values from a database directly as the output filename, allowing arbitrary file writes outside the report output directory. An attacker can embed a path traversal payload such as ../../../outside written.bin in the database to write files to arbitrary locations, potentially achieving code execution by overwriting executable files or configuration.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Valeapp