Description
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with local access. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-03
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Blix Email Blue Mail Calendar App’s FileDirectory.getFileFromUri method, where the _display_name parameter can be manipulated to perform a path traversal attack. The flaw falls under CWE‑22 and enables an attacker with local access to read or expose files outside the intended storage area, potentially revealing sensitive data. As the attack vector is limited to devices where the compromised app is installed, the impact is confined to the local user’s device data and confidentiality is at risk.

Affected Systems

Blix; Email Blue Mail Calendar App; version 2.2.305. No other product or version information is provided.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, but the vulnerability is publicly exploited. The exploit requires local access, meaning it does not pose a remote attack risk. It is not listed in the CISA KEV catalog, but the public availability of the exploit warrants caution. The risk level is moderate because local compromise is needed, yet the potential for sensitive file disclosure on the device makes it a significant concern for affected users.

Generated by OpenCVE AI on August 4, 2026 at 09:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest release of Email Blue Mail Calendar App once a vendor fix is issued or uninstall the app if no patch exists.
  • Configure Android permissions to restrict the app’s access to critical directories, limiting its ability to read sensitive files.
  • Monitor Blix for security advisories and employ a device management solution to enforce only approved app versions on user devices.

Generated by OpenCVE AI on August 4, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with local access. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Blix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDirectory.getFileFromUri path traversal
First Time appeared Blix
Blix email Blue Mail Calendar App
Weaknesses CWE-22
CPEs cpe:2.3:a:blix:email_blue_mail_calendar_app:*:*:*:*:*:*:*:*
Vendors & Products Blix
Blix email Blue Mail Calendar App
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Blix Email Blue Mail Calendar App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-05T14:23:54.821Z

Reserved: 2026-08-03T11:24:31.003Z

Link: CVE-2026-18648

cve-icon Vulnrichment

Updated: 2026-08-05T14:23:42.662Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T21:16:37.797

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-18648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:27Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')