


Perceptive Security
SOC/SIEM Consultancy

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget inst…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 18:06:04
Source:
nvd.nist.gov
Mobile & IoT, Operating Systems
AGL app-framework-main through version 17.1.12 contains a critical Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation process. The vulnerability allows attackers to write files anywhere on the filesystem due to insufficient validation of ZIP entry names in the is_valid_filename function. The zread extraction function executes before signature verification, meaning malicious files persist even if signature checks fail. This creates a serious security risk where unsigned or malicious widgets can achieve arbitrary file write capabilities on the target system.
Technical details
Mitigation steps:
Affected products:
AGL app-framework-main
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-37531
https://gerrit.automotivelinux.org/gerrit/src/app-framework-main
https://gist.github.com/sgInnora/8526eedcfd826d05ef1fc45d8f405643
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
