file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from ContentResolver.query() directly in file path construction without sanitization. A malicious Android app with a crafted ContentProvider can return a filename containing ../ sequences, causing the plugin to create arbitrary files and directories outside the intended cache directory within the victim app's internal storage. Existing files are not overwritten due to an existence check.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android File Picker Path Traversal Allowing Creation of Files Outside the Intended Directory | |
| Weaknesses | CWE-22 |
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from ContentResolver.query() directly in file path construction without sanitization. A malicious Android app with a crafted ContentProvider can return a filename containing ../ sequences, causing the plugin to create arbitrary files and directories outside the intended cache directory within the victim app's internal storage. Existing files are not overwritten due to an existence check. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T19:27:21.385Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38093
Updated: 2026-08-28T19:27:12.105Z
Status : Received
Published: 2026-08-28T16:17:46.793
Modified: 2026-08-28T20:17:27.200
Link: CVE-2026-38093
No data.
OpenCVE Enrichment
Updated: 2026-08-28T17:30:08Z