PT-2026-31464 · Abrignoni+1 · Valeapp
CVE-2026-40027
·
Published
2026-04-08
·
Updated
2026-04-08
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ALEAPP (Android Logs Events And Protobuf Parser) versions prior to 3.4.1
Description
The NQ Vault.py artifact parser contains a path traversal flaw. This occurs because the parser uses the
file name from variable, which is controlled by an attacker via a database, directly as the output filename. This allows arbitrary file writes outside the designated report output directory. By embedding a path traversal payload, such as ../../../outside written.bin, an attacker can write files to arbitrary locations, which may lead to code execution by overwriting configuration or executable files.Recommendations
Update ALEAPP (Android Logs Events And Protobuf Parser) to version 3.4.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Valeapp