Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android File Picker Path Traversal Allowing Creation of Files Outside the Intended Directory | |
| Weaknesses | CWE-22 |
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from ContentResolver.query() directly in file path construction without sanitization. A malicious Android app with a crafted ContentProvider can return a filename containing ../ sequences, causing the plugin to create arbitrary files and directories outside the intended cache directory within the victim app's internal storage. Existing files are not overwritten due to an existence check. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T14:47:15.784Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38093
No data.
Status : Received
Published: 2026-08-28T16:17:46.793
Modified: 2026-08-28T16:17:46.793
Link: CVE-2026-38093
No data.
OpenCVE Enrichment
Updated: 2026-08-28T17:30:08Z