CVE-2026-30281

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maru:neo.maru:2.0.23:*:*:*:*:android:*:*

History

06 Apr 2026, 15:13

Type Values Removed Values Added
First Time Maru
Maru neo.maru
CPE cpe:2.3:a:maru:neo.maru:2.0.23:*:*:*:*:android:*:*
References () https://github.com/Secsys-FDU/AF_CVEs/issues/21 - () https://github.com/Secsys-FDU/AF_CVEs/issues/21 - Exploit, Third Party Advisory
References () https://maru.xyz/ - () https://maru.xyz/ - Product
References () https://play.google.com/store/apps/details?id=neo.maru - () https://play.google.com/store/apps/details?id=neo.maru - Product
References () https://secsys.fudan.edu.cn/ - () https://secsys.fudan.edu.cn/ - Not Applicable

01 Apr 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-73

31 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 16:16

Updated : 2026-04-06 15:13


NVD link : CVE-2026-30281

Mitre link : CVE-2026-30281

CVE.ORG link : CVE-2026-30281


JSON object : View

Products Affected

maru

  • neo.maru
CWE
CWE-73

External Control of File Name or Path