๐Ÿ” CVE Alert

CVE-2026-108544

MEDIUM 6.3

Lippu Docx Reader Office Viewer App path traversal

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in Lippu Docx Reader Office Viewer App up to 1.4.5 on Android. This affects the function word.office.docxviewer.document.docx.reader.ViewTxt. Such manipulation of the argument _display_name leads to path traversal. The attack may be performed from remote.

CWE CWE-22
Vendor lippu
Product docx reader office viewer app
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for lippu docx reader office viewer app

Be the first to know when new medium vulnerabilities affecting lippu docx reader office viewer app are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Lippu / Docx Reader Office Viewer App
1.4.0 1.4.1 1.4.2 1.4.3 1.4.4 1.4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/416199 vuldb.com: https://vuldb.com/vuln/416199/cti vuldb.com: https://vuldb.com/cve/CVE-2026-108544 vuldb.com: https://vuldb.com/submit/954042 github.com: https://github.com/Secsys-FDU/AF_CVEs/issues/31

Credits

๐Ÿ” Secsys-FDU (VulDB User)