Executive brief
ALEAPP is an open-source digital forensics tool used to parse Android logs and events. A security flaw in its NQ Vault parser allows a malicious database file to write data to unauthorized locations on the investigator's computer. This could allow an attacker to overwrite system files or configuration settings, potentially leading to full system compromise when a forensic analyst processes a compromised device image.
Technical details
A path traversal vulnerability exists in the NQ_Vault.py artifact parser within ALEAPP through version 3.4.0. The root cause is the insecure use of the 'file_name_from' value retrieved from a database, which is passed directly to file system operations without sanitization. By providing a crafted database containing traversal sequences (e.g., '../../'), an attacker can force the application to write files outside of the intended report directory. This can be leveraged to overwrite executable files or configurations to achieve arbitrary code execution. The vulnerability requires a user to process a malicious data source (User Interaction) and has been addressed in subsequent commits by implementing filename sanitization and path confinement.
Affected products
- abrignoni ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0
Timeline
- 2026-03-02: other: Fix pull request submitted
- 2026-03-04: patched: Fix merged into main branch
- 2026-04-08: disclosed: Vulnerability published