CVE-2026-65996: GHSL-2026-106: Malicious deep links enable arbitrary file writes in OsmAnd - CVE-2026-65996
Published Oct 1, 2026
·Updated
A remote attacker can exploit path traversal in the OsmAnd /open-gpx deep link to fetch arbitrary URLs and write attacker-controlled GPX files within the app's scoped storage.
Affected Software
1 affected component
Osmand Osmand
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to cause OsmAnd to process a malicious `/open-gpx` deep link. The link can direct the app to fetch an arbitrary URL and use path traversal to write attacker-controlled GPX content in the app's scoped storage.
2
Is exploitation limited to files already available on the device?
No. The vulnerable deep link can fetch content from arbitrary URLs, allowing an attacker to supply a remote GPX file for writing.
3
Where can malicious files be written?
The available information states that writes occur within OsmAnd's scoped storage. It does not establish that an attacker can write outside that storage area.