Executive brief
aaptjs is a Node.js wrapper for the Android APK packaging tool (aapt). The remove function fails to validate filePath parameters, allowing an attacker to inject arbitrary shell commands that execute with the privileges of the application process. This could lead to complete system compromise, data theft, or denial of service depending on how the application is deployed.
Technical details
The vulnerability is a command injection flaw (CWE-77, CWE-78) in the remove function where user-supplied filePath parameters are directly concatenated into shell commands executed via the Node.js exec() function without proper sanitization or escaping. An attacker who can control the filePath input to the remove function can inject arbitrary shell metacharacters and commands. No authentication is required—this depends on whether the affected application exposes this function to untrusted input. The vulnerability affects aaptjs version 1.3.1 and likely all earlier versions. Patches or mitigations have not been publicly documented in the available advisory data.
Affected products
- shenzhim aaptjs 1.3.1 and earlier
Timeline
- 2020-10-02: disclosed: Issue reported on GitHub
- 2021-11-02: advisory: GitHub Security Advisory GHSA-9cq3-fj2h-ggj5 published