CVE-2026-18907
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
- Affected products
- Hi Browser
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-23
- NVD status
- Received
- Published
- 2026-08-05
- Attack patterns
- CAPEC-126
- Entry point
- Content-Disposition header
- Path
- /
CVE-2026-18907 at NVD
1 known exploit for CVE-2026-18907
Proof-of-concept code and exploit modules indexed by Sploitus