Junglewise Threat Intelligence

CVE-2026-42049: skylot jadx Groovy code injection in Gradle export

CVE-2026-42049 · Severity: info · CVSS 8.4 · Published 2026-07-14

Technologies: Skylot Jadx-Gui. Vendors: Skylot.

Executive brief

Jadx is a tool used by developers and security researchers to decompile Android applications (APKs) into readable Java code. A vulnerability exists where a specially crafted malicious APK can trick the tool into generating a compromised project file. If a user exports this project and then opens or builds it in a development environment like Android Studio, the attacker's hidden code will run on the user's computer, potentially leading to a full system takeover or data theft.

Technical details

A code injection vulnerability (CWE-94) exists in jadx prior to version 1.5.6. The issue resides in the Gradle export functionality, where the 'android:versionName' attribute from an APK's AndroidManifest.xml is inserted into the generated 'app/build.gradle' Groovy template without sanitization. An attacker can craft a malicious APK with a version name that breaks out of the Groovy string context (e.g., using quotes and semicolons). When a victim exports the project and subsequently opens it in an IDE or runs a Gradle build, the injected Groovy code executes with the privileges of the user. This has been fixed in version 1.5.6 by implementing proper string sanitization for Gradle script exports.

Affected products

  • skylot jadx-gui <= 1.5.5
  • skylot jadx < 1.5.6

Timeline

  • 2026-07-09: patched: Fix commit 5a6e660b4663d998d52c7dc4511299f3368ef611 pushed to GitHub.
  • 2026-07-10: advisory: GitHub Security Advisory GHSA-w6f5-h4x4-rfpj published.
  • 2026-07-14: disclosed: CVE-2026-42049 published to NVD.

References

Related threats