CVE-2026-30285
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-30285 is an arbitrary file overwrite vulnerability in the Zora: Post, Trade, Earn Crypto Android application (version 2.60.0), developed by Zora Labs, Inc. The flaw allows attackers to overwrite critical internal files via the app's file import process, potentially leading to arbitrary code execution or sensitive information exposure. It was disclosed and published on March 31, 2026, with a patch noted as available on the same date. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Secsys-FDU Issue).

Technical details

The root cause is insufficient security validation during the file import process in co.ourzora.app.MainActivity, classified as CWE-22 (Path Traversal). A malicious application can control both the filename and file content, using path traversal sequences to write arbitrary data to locations outside the intended directory within the app's internal storage. Because the app does not properly neutralize special elements in the constructed pathname, an attacker can target critical configuration or executable files. The attack requires no complex user interaction and can be triggered automatically once the victim opens a malicious app that initiates the file import (Secsys-FDU Issue, GitHub Advisory).

Impact

Successful exploitation can result in arbitrary code execution, exposure of sensitive information stored within the app, denial of service (app malfunction or failure to launch), and potential privilege escalation by overwriting executable or configuration files. An attacker who overwrites critical internal files could cause the app to execute attacker-controlled code in the context of the Zora application, potentially accessing cryptocurrency wallet credentials or other sensitive user data. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability (Secsys-FDU Issue, GitHub Advisory).

Exploitation steps

  1. Craft a malicious Android app: Develop a malicious Android application that, when opened, initiates a file import operation targeting the Zora app's file import interface (e.g., via an Android Intent directed at co.ourzora.app.MainActivity).
  2. Construct a path traversal payload: Prepare a file with a crafted filename containing path traversal sequences (e.g., ../../lib/target.so or ../../shared_prefs/config.xml) and attacker-controlled content.
  3. Trigger the import: Cause the victim to open the malicious app (no complex user interaction required); the malicious app automatically sends the crafted file to the Zora app's import handler.
  4. Overwrite internal files: The Zora app, lacking proper path validation, writes the attacker-supplied content to the traversed path within the app's internal storage, overwriting a critical configuration or executable file.
  5. Achieve objective: Depending on the overwritten file, the attacker may achieve arbitrary code execution (by replacing a native library or script), expose sensitive data (by replacing config files to redirect data), or cause denial of service (by corrupting essential app files) (Secsys-FDU Issue).

Indicators of compromise

  • File System: Unexpected modification timestamps on files within the Zora app's internal storage directory (/data/data/co.ourzora.app/); presence of unfamiliar or zero-byte files in subdirectories such as lib/, shared_prefs/, or files/.
  • Logs: Android system logs (logcat) showing unusual file write operations originating from co.ourzora.app.MainActivity; errors related to file integrity checks or unexpected file formats at app startup.
  • Process: Zora app crashing or failing to launch after a file import event; unexpected child processes or native library loads following an import operation.
  • Network: Unusual outbound network connections from the Zora app process following a file import, potentially indicating post-exploitation data exfiltration (Secsys-FDU Issue).

Mitigation and workarounds

Users should update the Zora: Post, Trade, Earn Crypto app to a version beyond 2.60.0, as a patch was made available on March 31, 2026. If an immediate update is not possible, users should avoid importing files from untrusted sources and restrict the app's file access permissions where feasible. Organizations managing devices with the Zora app should monitor for suspicious file import activity and consider temporarily disabling the app until patching is confirmed (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by Secsys-FDU, the security research lab at Fudan University, which published the disclosure via a GitHub issue on March 31, 2026. No notable vendor statements from Zora Labs, broader media coverage, or significant community discussion have been identified beyond the initial disclosure and advisory publication.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management