Junglewise Threat Intelligence

CVE-2026-12190: Genspark AI Workspace App arbitrary file write via path traversal

CVE-2026-12190 · Severity: medium · CVSS 5.3 · Published 2026-06-14

Executive brief

Genspark AI Workspace is an Android application for AI-driven productivity. A vulnerability in how the app handles shared files allows a malicious app installed on the same device to overwrite the Genspark app's internal data. This can lead to the corruption of user settings, session data, and authentication tokens, potentially causing the app to malfunction or allowing an attacker to manipulate the user's account state.

Technical details

The Genspark AI Workspace App (version 2.8.4) on Android contains a path traversal vulnerability, often referred to as a 'Dirty Stream' attack. The application's exported MainActivity handles ACTION_SEND and ACTION_VIEW intents by reading the '_display_name' column from a provided content URI and using it directly as a filename in the app's internal cache directory. Because the app fails to sanitize this name or validate the canonical path, a local malicious application can provide a name containing '../' sequences. This allows the attacker to write arbitrary files into the victim app's private data directories, including shared_prefs, databases, and code_cache. This can be used to overwrite critical configuration files like FlutterSharedPreferences.xml or session data.

Affected products

  • Genspark (iAI Lab) Genspark AI Workspace App 2.8.4

Timeline

  • 2026-06-14: disclosed: Vulnerability details published via VulDB and GitHub.
  • 2026-06-14: advisory: CVE-2026-12190 assigned.

References