CVE-2026-108544
Received Received - Intake

Path Traversal in Lippu Docx Reader Office Viewer App

Vulnerability report for CVE-2026-108544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A vulnerability was identified in Lippu Docx Reader Office Viewer App up to 1.4.5 on Android. This affects the function word.office.docxviewer.document.docx.reader.ViewTxt. Such manipulation of the argument _display_name leads to path traversal. The attack may be performed from remote.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Lippu Docx Reader Office Viewer App 1.4.0
Lippu Docx Reader Office Viewer App 1.4.1
Lippu Docx Reader Office Viewer App 1.4.2
Lippu Docx Reader Office Viewer App 1.4.3
Lippu Docx Reader Office Viewer App 1.4.4
Lippu Docx Reader Office Viewer App 1.4.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108544 is a path traversal vulnerability in the Lippu Docx Reader Office Viewer App for Android up to version 1.4.5. The flaw occurs in the function word.office.docxviewer.document.docx.reader.ViewTxt when handling the _display_name argument. Attackers can manipulate this to traverse file paths and overwrite sensitive files in the app's internal storage.

Detection Guidance

To detect this vulnerability, inspect the Docx Reader - Office Viewer app version on Android devices. Check if the installed version is up to 1.4.5. Look for signs of file overwrites in the app's internal storage, such as modified ServerConfig.xml or other configuration files. Monitor for app crashes or unexpected behavior after file imports.

Impact Analysis

This vulnerability allows attackers to overwrite critical app files like configuration or executable files. This could cause the app to malfunction, fail to launch, or execute arbitrary code. The attack requires minimal user interaction and can be triggered automatically when the victim opens a malicious app.

Compliance Impact

This vulnerability could lead to unauthorized file overwrites, potentially exposing or modifying sensitive data stored by the app. For GDPR, this may result in unauthorized access to personal data, violating principles of data protection and user consent. For HIPAA, if the app handles protected health information, file overwrites could compromise confidentiality or integrity of records.

Mitigation Strategies

Update the Lippu Docx Reader Office Viewer App to the latest version beyond 1.4.5 to patch the path traversal vulnerability. Avoid installing untrusted apps or opening files from unknown sources. Monitor app behavior for unexpected file modifications or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart