Sploitus

CVE-2026-18907

1 known exploit for CVE-2026-18907

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Affected products
Hi Browser
CVSS 3.1
7.5 HIGH
EPSS
0.6% (45th percentile)
Weakness
CWE-23
NVD status
Received
Published
2026-08-05
Attack patterns
CAPEC-126
Entry point
Content-Disposition header
Path
/
CVE-2026-18907 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-18907

Proof-of-concept code and exploit modules indexed by Sploitus