GHSL-2026-106: Malicious deep links enable arbitrary file writes in OsmAnd - CVE-2026-65996
Published Oct 1, 2026
·Updated
A remote attacker can exploit path traversal in the OsmAnd /open-gpx deep link to fetch arbitrary URLs and write attacker-controlled GPX files within the app's scoped storage.
Affected Software
1 affected component
Osmand Osmand
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Can this be exploited remotely?
Yes. A remote attacker can exploit the vulnerable deep-link handler.
2
What can an attacker control through the vulnerable handler?
The attacker can cause arbitrary URLs to be fetched and write attacker-controlled GPX files within the app's scoped storage.