Junglewise Threat Intelligence

CVE-2026-42447: skylot jadx-gui HTML injection in Summary tab

CVE-2026-42447 · Severity: low · CVSS 3.6 · Published 2026-07-14

Technologies: Skylot Jadx-Gui. Vendors: Skylot.

Executive brief

jadx is a popular tool used by developers and security researchers to decompile Android APK files into readable Java code. A vulnerability in the tool's graphical interface allows a malicious APK file to trigger unauthorized actions when opened. If a user views the 'Summary' tab of a specially crafted file, the application may disclose the user's IP address or attempt to interact with other software running on the user's local computer.

Technical details

A vulnerability exists in jadx-gui versions prior to 1.5.6 due to improper neutralization of input during HTML generation in SummaryNode.java. The application appends architecture names and counts derived from .so file paths within an APK directly into an HtmlPanel using builder.append() instead of builder.escape(). An attacker can exploit this by crafting an APK with a ZIP entry name containing URL-encoded HTML tags (e.g., <img> tags). When a victim opens the APK and views the Summary tab, the injected HTML is rendered, allowing for out-of-band requests (SSRF-like behavior) that can leak the victim's IP address or interact with services on localhost. This issue is primarily exploitable on non-Windows systems, as Windows path validation typically rejects the required special characters. The issue is fixed in version 1.5.6.

Affected products

  • skylot jadx-gui < 1.5.6

Timeline

  • 2026-07-10: patched: Version 1.5.6 released
  • 2026-07-10: advisory: GitHub Security Advisory published
  • 2026-07-14: disclosed: CVE-2026-42447 published to NVD

References

Related threats