PT-2026-84584 · Airasia · Airasia Move App

·

CVE-2026-84431

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions AirAsia MOVE App versions prior to 12.47.2
Description A path traversal issue exists in the com.airasia.mobile component. This occurs within the getRealPath() function of com.airasia.core.utils.RealPathUtil when the display name argument is manipulated. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables that reference files with input that is not properly neutralized.
Recommendations Update AirAsia MOVE App to version 12.47.2 or later. As a temporary workaround, restrict the use of the display name argument within the getRealPath() function.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84431

Affected Products

Airasia Move App