{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-18907", "assignerOrgId": "907edf6c-bf03-423e-ab1a-8da27e1aa1ea", "state": "PUBLISHED", "assignerShortName": "TECNOMobile", "dateReserved": "2026-08-05T01:25:36.338Z", "datePublished": "2026-08-05T01:47:16.191Z", "dateUpdated": "2026-08-05T01:47:16.191Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "907edf6c-bf03-423e-ab1a-8da27e1aa1ea", "shortName": "TECNOMobile", "dateUpdated": "2026-08-05T01:47:16.191Z" }, "title": "PathTravelsal Vulnerability in com.talpa.hibrowser", "datePublic": "2026-08-05T01:45:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-23", "description": "CWE-23 Relative path traversal", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-126", "descriptions": [ { "lang": "en", "value": "CAPEC-126 Path Traversal" } ] } ], "affected": [ { "vendor": "TECNO Mobile", "product": "Hi Browser", "packageName": "com.talpa.hibrowser", "versions": [ { "status": "affected", "version": "2.23.1.1" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.  " } ] } ], "references": [ { "url": "https://security.tecno.com/SRC/securityUpdates" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.4" } } } }