Zora: Post, Trade, Earn Crypto Arbitrary File Overwrite Vulnerability Allowing Code Execution

Vulnerability

An arbitrary file overwrite vulnerability has been identified in the Zora: Post, Trade, Earn Crypto app, version 2.60.0. This vulnerability allows attackers to overwrite critical internal files through the file import process, potentially leading to arbitrary code execution or exposure of sensitive information. The issue arises from inadequate security validation when handling imported files, enabling a malicious app to manipulate filenames and contents to overwrite important files in the app's internal storage. Such modifications can cause the app to malfunction, fail to launch, or execute unauthorized code. The vulnerability can be exploited automatically once the victim opens the malicious app, without requiring complex user interaction.

Impact

Exploitation of this vulnerability can result in arbitrary code execution or unauthorized modification of internal files, potentially leading to privilege escalation or causing the app to malfunction.

Reproduction

To reproduce this vulnerability, a malicious app must be created that exploits the file import process by using path traversal techniques to overwrite critical files in the Zora app's internal storage. Once the malicious app is installed, it can automatically trigger the overwrite without user intervention.

Added: Mar 31, 2026, 8:47 PM
Updated: Mar 31, 2026, 8:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.8
remediation
0.0
relevance
5.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.