Description
A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-04
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the t5.l.c function of ZomboDroid Meme Generator App 4.6830 allows local path traversal, meaning an attacker with local device access can manipulate file paths to read or potentially overwrite files outside the intended directory. The weakness is a classic directory traversal flaw (CWE‑22). Because the exploit requires the attacker to be on the device, it does not enable remote compromise, but it can expose sensitive local data.

Affected Systems

The affected product is the ZomboDroid Meme Generator App 4.6830 for Android, specifically the component com.zombodroid.MemeGenerator’s t5.l.c function.

Risk and Exploitability

The CVSS base score of 4.8 indicates a moderate impact with local scope; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Local access to the device is required, so the attack vector is limited to a user who has physically or remotely gained local privileges on the victim’s Android device. The vulnerability has been publicly disclosed, indicating that potential attackers could attempt path traversal once an affected device is located.

Generated by OpenCVE AI on August 5, 2026 at 01:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any vendor‑released fix or newer release of ZomboDroid Meme Generator that addresses the path traversal flaw.
  • Restrict the app’s file‑system permissions by tightening Android sandbox settings, ensuring the vulnerable component cannot access directories outside its intended scope.
  • Monitor device logs for anomalous file‑access patterns and audit local users for unauthorized path traversal attempts.

Generated by OpenCVE AI on August 5, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
First Time appeared Zombodroid
Zombodroid meme Generator App
Weaknesses CWE-22
CPEs cpe:2.3:a:zombodroid:meme_generator_app:*:*:*:*:*:*:*:*
Vendors & Products Zombodroid
Zombodroid meme Generator App
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zombodroid Meme Generator App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T23:45:10.459Z

Reserved: 2026-08-04T15:51:55.217Z

Link: CVE-2026-18853

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')