{"id":"CVE-2026-54684","summary":"jadx: XAPK archive entries with absolute paths can plant drop-in plugins and achieve code execution on the next jadx run","details":"jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outside the intended XAPK plugin temporary unpack directory because XApkLoader resolves each entry name directly with tmpDir.resolve(fileName) after a CWD-based ZIP security check. When jadx is launched from a directory that is an ancestor of the config directory, the arbitrary write can plant a JAR in plugins/dropins, and the next jadx run loads the JAR with URLClassLoader and ServiceLoader, executing attacker-controlled plugin code. This issue is fixed in version 1.5.6.","aliases":["GHSA-gpvc-ccw7-744v"],"modified":"2026-08-12T16:41:16.561753Z","published":"2026-07-14T21:46:29.373Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54684.json"},"references":[{"type":"WEB","url":"https://github.com/skylot/jadx/releases/tag/v1.5.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54684.json"},{"type":"ADVISORY","url":"https://github.com/skylot/jadx/security/advisories/GHSA-gpvc-ccw7-744v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54684"},{"type":"FIX","url":"https://github.com/skylot/jadx/commit/a74bb07d6eebaf4da5c2b2cbc4d3c0c3cb7517cb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/skylot/jadx","events":[{"introduced":"13e934ce4d1af67e8adea7373a11649c2abdee43"},{"fixed":"a74bb07d6eebaf4da5c2b2cbc4d3c0c3cb7517cb"},{"fixed":"28ff15e4ae69950aebea110a13e5ab895d234dfc"}],"database_specific":{"extracted_events":[{"introduced":"1.5.2"},{"fixed":"1.5.6"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.5.4","v1.5.3","v1.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54684.json","vanir_signatures_modified":"2026-08-12T16:41:16Z","vanir_signatures":[{"digest":{"line_hashes":["118014642406769659103776073437968672592","265775248268315719426659794105053302902","172973484744477447613924586852770070408","26135232408086617525104654092153467177"],"threshold":0.9},"id":"CVE-2026-54684-7f5b5235","signature_type":"Line","signature_version":"v1","source":"https://github.com/skylot/jadx/commit/a74bb07d6eebaf4da5c2b2cbc4d3c0c3cb7517cb","target":{"file":"jadx-commons/jadx-zip/src/main/java/jadx/zip/security/JadxZipSecurity.java"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/skylot/jadx/commit/a74bb07d6eebaf4da5c2b2cbc4d3c0c3cb7517cb","target":{"function":"isValidEntryName","file":"jadx-commons/jadx-zip/src/main/java/jadx/zip/security/JadxZipSecurity.java"},"deprecated":false,"digest":{"function_hash":"58550663106364603330380777435195939371","length":603},"id":"CVE-2026-54684-da5fee61","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}