CVE-2026-5682: Meesho Online Shopping App

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

Affected products

  • Meesho Online Shopping App: version 27.0 only; version 27.1 only; version 27.2 only; version 27.3 only

Published 2026-04-06. Last modified 2026-07-24.