CVE-2026-5682 Details
Description
A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
A cryptographic vulnerability exists in the Meesho Online Shopping App for Android, in versions up to 27.3. The issue arises in the component 'com.meesho.supply', specifically within the file '/api/endpoint'. The vulnerability involves the use of the AES encryption algorithm in CBC mode, which lacks proper integrity protection, combined with a weak key derivation process that relies on the deprecated MD5 algorithm. This flawed implementation allows for interception and modification of encrypted data without detection, potentially leading to unauthorized actions or exposure of sensitive information. The vulnerability is classified under CWE-327, indicating the use of a risky cryptographic algorithm.
No specific mitigation is known for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 6, 2026CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/honestcorrupt/MEESHO-CVE | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/submit/792717 | [email protected] | Technical Description |
| https://vuldb.com/vuln/355509 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/355509/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Meesho Online Shopping App | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 6, 2026 | New CVE Received | [email protected] |
Volerion