CVE-2026-58460Disclosure

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted _display_name value containing dot-dot path components through a malicious ContentProvider. Attackers can fire an explicit ACTION_SEND intent at the consuming app's exported share-receiver activity to overwrite arbitrary files in the consuming app's private data directory, including databases, shared preferences, and cached configuration, with attacker-controlled content.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-02: 2Mentions · 2026-07-07: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-07: 107-0207-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-07-071
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-58460 react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache … https://www.cve.org/CVERecord?id=CVE-2026-58460

    Post summary

    The post announces a path traversal flaw in react-native-receive-sharing-intent, enabling file write outside the intended cache, and provides a CVE link for further details.

    01000613
    57.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH severity CVE-2026-58460 (CVSS 7.7) Path traversal flaw in react-native-receive-sharing-intent allows malicious apps to overwrite files in victim app's private directory via crafted ACTION_SEND intent. Impact: Data integrity & availability compromise https://t.co/eGXQTCjQTi

    Post summary

    The tweet announces a high‑severity path‑traversal flaw in react‑native‑receive‑sharing‑intent, describing its impact and CVSS score, but provides no proof‑of‑concept, exploit, active attack evidence, or repair guidance.

    0000045
    66 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58460 react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache … https://www.cve.org/CVERecord?id=CVE-2026-58460 ----- Traducción: CVE-2026-58460 rea… http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE‑2026‑58460, a path‑traversal bug in react‑native‑receive‑sharing‑intent that permits a malicious app to write files outside its cache space.

    0000049
    91 followersView on X

Explore more