Sceawere
Vulnerability Detail
CVE-2026-108544UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Lippu Docx Reader Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 2h ago
- Vendor
- Lippu
- Product
- Docx Reader Office Viewer App
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in Lippu Docx Reader Office Viewer App up to 1.4.5 on Android. This affects the function word.office.docxviewer.document.docx.reader.ViewTxt. Such manipulation of the argument _display_name leads to path traversal. The attack may be performed from remote.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-11T08:16:33.913Z",
"pubdate": "2026-10-11T08:16:33.913Z",
"executiveSummary": "A path traversal vulnerability has been identified in Lippu Docx Reader Office Viewer App versions up to 1.4.5 for Android. The flaw resides within the application's document handling logic, specifically affecting the 'word.office.docxviewer.document.docx.reader.ViewTxt' function. An attacker can exploit this vulnerability via a maliciously crafted '_display_name' argument to escape the intended application sandbox or directory boundaries.\nThe vulnerability allows for unauthorized file system access, potentially leading to the exposure of sensitive user data or system files. Because the attack can be performed remotely, it represents a significant security risk for mobile users. Successful exploitation requires the application to process a crafted input, enabling the attacker to perform arbitrary file read operations by manipulating file paths to access files outside of the application's designated storage directory.",
"technicalDetails": "The vulnerability exists in the 'word.office.docxviewer.document.docx.reader.ViewTxt' function, which fails to properly sanitize the '_display_name' argument before utilizing it in file system operations. In the Android ecosystem, applications often manage files via Intents or content providers; this specific component improperly validates the file path provided through the '_display_name' parameter, failing to implement sufficient canonicalization or boundary checks.\nThe root cause is a lack of input validation and path sanitization. An attacker can supply a specially crafted '_display_name' containing directory traversal sequences (such as '../'). When the application processes this input, it resolves the relative path against the application's private directory, effectively traversing outside the intended storage root. This allows the application to access files that the user did not intend to open, or potentially system-sensitive files if the application's permission model is misconfigured.\nThe attack flow proceeds as follows: 1) An attacker delivers a malicious file or triggers an intent that influences the '_display_name' parameter passed to the 'ViewTxt' component. 2) The application attempts to resolve or open the file referenced by this parameter. 3) Because the input is not sanitized to strip path traversal sequences, the underlying system API resolves the path to an arbitrary location on the device's internal storage or external SD card, depending on the application's manifest permissions. 4) The 'ViewTxt' function then reads or displays the content of the targeted file.\nThis vulnerability is remotely exploitable, meaning the impact can be realized if a user opens a malicious document or interacts with an external trigger that passes the crafted argument. The impact is significant as it facilitates unauthorized access to private data stored within the app's local storage or other areas accessible to the application's process context. As this does not require a complex memory corruption exploit, the barrier to entry for an attacker is relatively low, relying strictly on the application's failure to enforce logical path boundaries during file read operations."
}