---
id: CVE-2026-5682
title: >-
  A vulnerability has been found in Meesho Online Shopping App up to 27.3 on
  Android
summary: >-
  A vulnerability has been found in Meesho Online Shopping App up to 27.3 on
  Android. Affected is an unknown function of the file /api/endpoint of the
  component com.meesho.supply. Such manipulation leads to risky cryptographic
  algorithm. T…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-310
  - CWE-327
published: '2026-04-06'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5682'
references:
  - url: 'https://github.com/honestcorrupt/MEESHO-CVE'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/792717'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355509'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355509/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - exploit-available
epss: 0.00188
epssPercentile: 0.08645
ingestedAt: '2026-07-24T09:23:52.356Z'
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/honestcorrupt/meesho-android-improper-encryption-cve-2026-5682
  checkedAt: '2026-09-23T07:14:25.062Z'
exploitAvailable: true
---

## Overview

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
