CVE-2026-38093 | file_picker Plugin up to 10.3.10 Android Implementation FileUtils.kt openFileStream DISPLAY_NAME path traversal

SecurityVulns

A vulnerability, which was classified as problematic, was found in file_picker Plugin up to 10.3.10. Affected by this vulnerability is the function openFileStream of the file FileUtils.kt of the component Android Implementation. Executing a manipulation of the argument DISPLAY_NAME can lead to path traversal.

This vulnerability appears as CVE-2026-38093. The attack requires local access. There is no available exploit.VulDB Recent EntriesRead More