PT-2026-58854 · Jadx · Jadx

CVE-2026-42447

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jadx versions prior to 1.5.6
Description The Summary tab in jadx-gui allows HTML injection because the SummaryNode.java file appends arches and perArchCount values, derived from .so file path components within an APK, into an HTML panel without proper escaping. An attacker can use a malicious APK containing an HTML URL-encoded ZIP entry name to force the rendering of arbitrary HTML. This can lead to out-of-band requests, disclosure of the victim's IP address, or interaction with locally exposed applications.
Recommendations Update to version 1.5.6.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42447
GHSA-JWV3-Q635-W9M4

Affected Products

Jadx