Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
jadx: XAPK archive entries with absolute paths can plant drop-in plugins and achieve code execution on the next jadx run
CVE-2026-54684
Description
jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outside the intended XAPK plugin temporary unpack directory because XApkLoader resolves each entry name directly with tmpDir.resolve(fileName) after a CWD-based ZIP security check. When jadx is launched from a directory that is an ancestor of the config directory, the arbitrary write can plant a JAR in plugins/dropins, and the next jadx run loads the JAR with URLClassLoader and ServiceLoader, executing attacker-controlled plugin code. This issue is fixed in version 1.5.6.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/skylot/jadx/commit/a74bb07d6eebaf4da5c2b2cbc4d3c0c3cb7517cbmitrex_refsource_MISC
- github.com/skylot/jadx/releases/tag/v1.5.6mitrex_refsource_MISC
- github.com/skylot/jadx/security/advisories/GHSA-gpvc-ccw7-744vmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.