LOW 1.9 NVD
CVE-2026-84431
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of th
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
- https://docs.google.com/document/d/19qRCn6NWF2UE4urLXMXKgW555PHhnQiw/edit?usp=sharing&ouid
- https://vuldb.com/cve/CVE-2026-84431
- https://vuldb.com/submit/884138
- https://vuldb.com/vuln/397798
- https://vuldb.com/vuln/397798/cti
This low severity vulnerability with a CVSS score of 1.9 was published on 2026-09-02 via NVD.
vulnfeed aggregates 11552 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.