CVE-2026-84431 | AirAsia MOVE App up to 12.47.1 on Android com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath _display_name path traversal

SecurityVulns

A vulnerability, which was classified as problematic, has been found in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal.

This vulnerability is reported as CVE-2026-84431. The attack requires a local approach. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More