PT-2026-58853 · Jadx · Jadx
CVE-2026-42049
·
Published
2026-07-14
·
Updated
2026-07-14
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
jadx versions prior to 1.5.6
Description
When exporting a decompiled APK as an Android Gradle project, the software inserts the
android:versionName value from the AndroidManifest into the generated app/build.gradle Groovy template without proper sanitization. A malicious APK can break out of the string context, allowing the execution of attacker-controlled Groovy code on the victim machine when the exported Gradle project is opened or built.Recommendations
Update to version 1.5.6.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jadx