GHSA-m8mh-x359-vm8m
HIGHCVE-2026-39973A path traversal vulnerability in brut/androlib/res/decoder/ResFileDecoder.java allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (apktool d). This is a security regression introduced in commit [e10a045](https://github.com/iBotPeaches/Apktool/commit/e10a0450c7afcd9462c0b76bcbff0e7428b92bdd#diff-cd531ebe1014bfd18185bf21585ca5cdb16fbcb07703ebc47949a
- Affected
- >= 3.0.0, < 3.0.2
- Fixed in
- 3.0.2
- Weakness
- CWE-22
- Published
- 2026-04-23
- Source
- github