CVE-2026-18648 | Blix Email Blue Mail Calendar App 2.2.305 react-native-receive-sharing-intent _display_name path traversal

SecurityVulns

A vulnerability was found in Blix Email Blue Mail Calendar App 2.2.305. It has been declared as critical. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal.

This vulnerability is identified as CVE-2026-18648. The attack is only possible with local access. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More