CVE-2026-58460: react-native-receive-sharing-intent Path Traversal via _display_name

Published Jul 2, 2026
·
Updated

react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted displayname value containing dot-dot path components through a malicious ContentProvider. Attackers can fire an explicit ACTIONSEND intent at the consuming app's exported share-receiver activity to overwrite arbitrary files in the consuming app's private data directory, including databases, shared preferences, and cached configuration, with attacker-controlled content.

Affected Software

1 affected component
react-native-receive-sharing-intent

Event History

Jul 2, 2026
CVE Published
via MITRE·08:10 PM
Data Sourced
via MITRE·08:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-58460?

The severity of CVE-2026-58460 is rated as high with a score of 7.

2

How does CVE-2026-58460 impact application security?

CVE-2026-58460 allows a malicious co-resident application to perform path traversal, potentially leading to unauthorized file writing.

3

How can I fix CVE-2026-58460?

To fix CVE-2026-58460, update the react-native-receive-sharing-intent to the latest version that addresses the path traversal vulnerability.

4

What types of applications are affected by CVE-2026-58460?

CVE-2026-58460 affects Android applications using react-native-receive-sharing-intent that do not properly validate the _display_name input.

5

Who is at risk from CVE-2026-58460?

Users and developers of applications utilizing react-native-receive-sharing-intent are at risk of exploitation from this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203