CVE-2026-25477: Path Traversal Via Unsanitized App Id

Constructing file paths directly from a potentially user-influenced `bundleIdentifier` or `appId` can lead to path traversal vulnerabilities. Attackers can provide identifiers with traversal sequences like `../` to access or write outside the intended directory. Ensure the identifier is properly sanitized (e.g., securely hashed) on all platforms before using

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-25477-path-traversal-via-unsanitized-app-id --engine opengrep

Description

Constructing file paths directly from a potentially user-influenced `bundleIdentifier` or `appId` can lead to path traversal vulnerabilities. Attackers can provide identifiers with traversal sequences like `../` to access or write outside the intended directory. Ensure the identifier is properly sanitized (e.g., securely hashed) on all platforms before using