Description
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Published: 2026-08-03
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE exposes a flaw where the com.meesho.supply component of the Meesho Online Shopping App mishandles user‑supplied parameters such as user_id, phone number, email address, and name. This misuse allows the application to write these values to persistent storage in an unencrypted form, a violation of CWE‑310 (Sensitive Data Exposure) and CWE‑312 (Cleartext Storage of Sensitive Information). An attacker who can influence these arguments can cause the device to permanently record personal data in plain text, which any local or physically compromised user could later read.

Affected Systems

Affected version set includes all builds of the Meesho Online Shopping App released up to 2026‑06‑07 on Android. No specific sub‑versions are listed beyond this date marker, so any installation of the app on Android that contains the com.meesho.supply module is considered vulnerable. The vendor is Meesho and the product is the Meesho Online Shopping App.

Risk and Exploitability

The CVSS base score of 2.4 indicates low severity, and the EPSS score is less than 1%, indicating a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local to the physical device; an attacker must manipulate the argument values directly on the handheld device. Although the flaw does not grant remote code execution or system compromise, once the data is written it can be retrieved by anyone with physical or local access to the device.

Generated by OpenCVE AI on August 4, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Refactor the app so that user_id, phone number, email, and name are encrypted or otherwise protected before writing to local storage, thereby addressing CWE-312.
  • Enforce strict input validation for these fields to prevent manipulation that leads to data capture, mitigating CWE-310.
  • When a vendor patch becomes available, update the Meesho app to the latest release; until then, consider uninstalling or avoiding use of the affected component.

Generated by OpenCVE AI on August 4, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Title Meesho Online Shopping App com.meesho.supply cleartext storage
First Time appeared Meesho
Meesho online Shopping App
Weaknesses CWE-310
CWE-312
CPEs cpe:2.3:a:meesho:online_shopping_app:*:*:*:*:*:*:*:*
Vendors & Products Meesho
Meesho online Shopping App
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.1, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Meesho Online Shopping App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T13:19:02.255Z

Reserved: 2026-08-02T20:44:04.393Z

Link: CVE-2026-18591

cve-icon Vulnrichment

Updated: 2026-08-03T13:18:58.231Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T08:17:18.823

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:45:04Z

Weaknesses