PT-2026-58854 · Jadx · Jadx
CVE-2026-42447
·
Published
2026-07-14
·
Updated
2026-07-14
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
jadx versions prior to 1.5.6
Description
The Summary tab in jadx-gui allows HTML injection because the
SummaryNode.java file appends arches and perArchCount values, derived from .so file path components within an APK, into an HTML panel without proper escaping. An attacker can use a malicious APK containing an HTML URL-encoded ZIP entry name to force the rendering of arbitrary HTML. This can lead to out-of-band requests, disclosure of the victim's IP address, or interaction with locally exposed applications.Recommendations
Update to version 1.5.6.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jadx