CVE-2026-7085Disclosure

LOWCVSS 1.3 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts of the component downloadApp Endpoint. This manipulation of the argument url causes path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The real existence of this vulnerability is still doubted at the moment. The vendor explains in a reply to the issue report, that "[t]his interface is used for online updates, and the update URL has been statically compiled in the official code repository. Unless users modify the code, the requested address will be the official source address."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-27: 3Technical Details · 2026-04-27: 304-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7085 A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts o… https://www.cve.org/CVERecord?id=CVE-2026-7085

    Post summary

    The text identifies CVE-2026-7085 in HBAI-Ltd Toonflow-app up to version 1.1.1, naming the vulnerable function and file location, but offers no PoC, exploitation details, or mitigation information.

    0000091
    57.3K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7085 📊 Severity: 5.0 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7085 #CVE-2026-7085 #CVE #Medium #CyberSecurity #InfoSec https://t.co/ojz4dv2DQA

    Post summary

    The tweet merely announces the existence and basic severity of CVE‑2026‑7085 without providing any exploit code, patch details, or evidence of active exploitation.

    0000056
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7085 Path Traversal in HBAI-Ltd Toonflow-app Up to Version 1.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7085

    Post summary

    Disclosed a path‑traversal vulnerability (CVE‑2026‑7085) in HBAI‑Ltd Toonflow‑app version 1.1.1, with no PoC, exploit, or patch details provided.

    0000050
    4.0K followersView on X

Explore more