External risk intelligence

Maru Neo Maru Arbitrary File Overwrite Leading to Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-30281

The affected product is a mobile application (Android), which typically operates as a client-side tool on end-user devices. File import processes in such applications are generally triggered by local user interaction and are not exposed as internet-facing services or gateways.

Maru Neo Maru

2.0.23

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in a MaruNuri application allows an attacker to overwrite internal files through a file import process, potentially leading to code execution or data exposure. The main concern is confirming relevance and exposure given the nature of the affected technology.

  • File import flaw can overwrite critical files.
  • Matters for potential code execution or data exposure.
  • Confirm if this app is in use and exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a vulnerability in the file import process of a specific application, potentially starting from the internet. This process, when improperly handled, allows for the overwrite of critical internal files, which can then lead to attackers executing arbitrary code or accessing sensitive information.

  • No authentication or user interaction required.
  • Triggered by importing a crafted file.
  • Risk of code execution or data exposure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to overwrite critical internal files within the application when supported by the advisory. This could lead to the execution of arbitrary code or the exposure of sensitive information stored by the application.

  • Application files and sensitive data.
  • Via the file import process.
  • Arbitrary code execution or data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

The arbitrary file overwrite vulnerability in MaruNuri LLC's Neo.Maru application requires immediate attention from application owners and potentially the vendor-management team. The first practical step is to identify all instances of the application, confirm their reachability and business criticality, and then determine the accountable owner for remediation planning.

  • Application owners must resolve.
  • Verify application reachability and criticality.
  • Coordinate vendor support for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Neo.Maru application?

Neo.Maru is a mobile software application developed by MaruNuri LLC for the Android operating system. Users typically employ this tool on their personal or enterprise mobile devices to manage and import specific file types, serving as a client-side utility rather than a server-based infrastructure component.

What does CVE-2026-30281 mean?

This vulnerability is classified as CWE-73, an External Control of File Name or Path. In plain terms, the application fails to safely validate files during the import process. This allows a malicious file to bypass intended restrictions and overwrite critical internal application files, which can lead to unauthorized code execution or the exposure of sensitive data.

How is this file overwrite triggered?

The vulnerability is triggered when the application processes a specially crafted file during its import routine. The flaw does not require the attacker to have previous authentication or specific user interaction with the app to initiate the overwrite. However, simply having the app installed is not enough; the import function must be actively invoked for the malicious file to take effect.

Is my device at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is considered unlikely to pose a broad risk. Because Neo.Maru is a mobile Android application, it typically functions as a client-side tool. It does not operate as an internet-facing service or network gateway, meaning it lacks the common attack surface usually targeted by remote, unauthenticated exploits.

What steps should I take regarding CVE-2026-30281?

If your organization uses Neo.Maru, your first priority is to locate and inventory all devices running the affected version. Assess whether the application is critical to your operations and identify the internal owner responsible for it. Coordinate with your vendor-management team to track updates and determine when a fix is available for deployment.

References