External risk intelligence

Zora Post Trade Earn Crypto Arbitrary File Overwrite Leading to Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-30285

The vulnerability affects a mobile application (Zora for Android) via its file import process. Mobile applications are typically client-side software rather than internet-facing services, gateways, or web applications, making public internet exposure of this specific import function unlikely.

Path Traversal

Zora

2.60.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability found in a cryptocurrency application that could allow attackers to overwrite important files, potentially leading to code execution or data exposure. The primary concern is to confirm if this specific application and version are in use within the organization, as the vulnerability is exploitable remotely without user interaction.

  • Attackers can overwrite critical application files.
  • It allows remote code execution and data exposure.
  • Confirm relevance and exposure within the organization.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted file through the application's import feature. Because no authentication is required, an unauthenticated attacker could initiate this process remotely. Successful exploitation allows the attacker to overwrite important internal files, which could lead to arbitrary code execution or the exposure of sensitive information.

  • No authentication needed for access.
  • Triggered via file import process.
  • Leads to code execution or data exposure.

Live Threat

Current exploitation, exposure, and threat context

Attackers could overwrite critical internal files within the Zora application, potentially leading to the execution of arbitrary code or the exposure of sensitive information, when the file import feature is utilized.

  • Application's internal files could be overwritten.
  • Attackers may exploit the file import process.
  • Could lead to code execution or info exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Zora mobile application's file import process could allow for arbitrary file overwrites and subsequent code execution or data exposure. The first practical step is for the application owner or the team managing the Zora mobile deployment to identify all instances of the affected application version, determine business criticality and external reachability, and then plan remediation based on the assessed risk.

  • Application owners should own the issue.
  • Verify external reachability and business impact.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Zora: Post, Trade, Earn Crypto application?

Zora is a cryptocurrency mobile app for Android. Specifically, version 2.60.0 includes a file import mechanism that is the focus of this security advisory.

How is CVE-2026-30285 classified?

This vulnerability is classified as CWE-22, which is the improper limitation of a pathname to a restricted directory. It means the application fails to adequately restrict where files are written during the import process.

How is this file overwrite vulnerability triggered?

The flaw is triggered through the application's file import feature. An attacker can supply a specially crafted file to overwrite critical internal application data. This process does not require user interaction or authentication to initiate.

Why is the risk to this application considered limited?

According to the Halo Surface Signal, this vulnerability affects a client-side mobile application. Because the affected file import function is not typically exposed to the public internet, the likelihood of remote exploitation is assessed as very unlikely.

What actions should be taken to address this issue?

Organizations should first identify all instances of Zora version 2.60.0 within their mobile device environment. Following identification, teams should assess business criticality and plan for updates or remediation based on their specific risk profile.

References