{"id":"CVE-2026-18907","title":"Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.","summary":"Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-23"],"published":"2026-08-05","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:46:07.450","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18907","references":[{"url":"https://security.tecno.com/SRC/securityUpdates","label":"907edf6c-bf03-423e-ab1a-8da27e1aa1ea"}],"tags":["nvd","exploit-available"],"epss":0.00661,"epssPercentile":0.4983,"exploits":{"github":1,"githubRepos":["https://github.com/Hunt-Benito/two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal"],"checkedAt":"2026-09-21T15:28:17.134Z"},"exploitAvailable":true,"ingestedAt":"2026-09-09T16:14:05.511Z","slug":"CVE-2026-18907","body":"## Overview\n\nPath Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}