
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30285 is an arbitrary file overwrite vulnerability in the Zora: Post, Trade, Earn Crypto Android application (version 2.60.0), developed by Zora Labs, Inc. The flaw allows attackers to overwrite critical internal files via the app's file import process, potentially leading to arbitrary code execution or sensitive information exposure. It was disclosed and published on March 31, 2026, with a patch noted as available on the same date. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Secsys-FDU Issue).
The root cause is insufficient security validation during the file import process in co.ourzora.app.MainActivity, classified as CWE-22 (Path Traversal). A malicious application can control both the filename and file content, using path traversal sequences to write arbitrary data to locations outside the intended directory within the app's internal storage. Because the app does not properly neutralize special elements in the constructed pathname, an attacker can target critical configuration or executable files. The attack requires no complex user interaction and can be triggered automatically once the victim opens a malicious app that initiates the file import (Secsys-FDU Issue, GitHub Advisory).
Successful exploitation can result in arbitrary code execution, exposure of sensitive information stored within the app, denial of service (app malfunction or failure to launch), and potential privilege escalation by overwriting executable or configuration files. An attacker who overwrites critical internal files could cause the app to execute attacker-controlled code in the context of the Zora application, potentially accessing cryptocurrency wallet credentials or other sensitive user data. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability (Secsys-FDU Issue, GitHub Advisory).
co.ourzora.app.MainActivity).../../lib/target.so or ../../shared_prefs/config.xml) and attacker-controlled content./data/data/co.ourzora.app/); presence of unfamiliar or zero-byte files in subdirectories such as lib/, shared_prefs/, or files/.logcat) showing unusual file write operations originating from co.ourzora.app.MainActivity; errors related to file integrity checks or unexpected file formats at app startup.Users should update the Zora: Post, Trade, Earn Crypto app to a version beyond 2.60.0, as a patch was made available on March 31, 2026. If an immediate update is not possible, users should avoid importing files from untrusted sources and restrict the app's file access permissions where feasible. Organizations managing devices with the Zora app should monitor for suspicious file import activity and consider temporarily disabling the app until patching is confirmed (GitHub Advisory).
The vulnerability was discovered and reported by Secsys-FDU, the security research lab at Fudan University, which published the disclosure via a GitHub issue on March 31, 2026. No notable vendor statements from Zora Labs, broader media coverage, or significant community discussion have been identified beyond the initial disclosure and advisory publication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."