PT-2025-3026 · Unknown · Image Picker+1
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
image picker versions prior to 0.8.12+18
image picker android versions prior to 0.8.12+18
Description
The file names constructed within image picker are missing sanitization checks, leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using the app and could potentially override internal files in the app cache.
Recommendations
For image picker versions prior to 0.8.12+18, update to the latest version of image picker android that contains the changes to address this issue.
For image picker android versions prior to 0.8.12+18, update to version 0.8.12+18 or later to resolve the vulnerability.
Exploit
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Image Picker
Image Picker Android