CVE-2026-39973Disclosure(apktool / apktool)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apktool apktool systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a security regression introduced in commit e10a045 (PR #4041, December 12, 2025), which removed the `BrutIO.sanitizePath()` call that previously prevented path traversal in resource file output paths. An attacker can embed `../` sequences in the `resources.arsc` Type String Pool to escape the output directory and write files to arbitrary locations, including `~/.ssh/config`, `~/.bashrc`, or Windows Startup folders, escalating to RCE. The fix in version 3.0.2 re-introduces `BrutIO.sanitizePath()` in `ResFileDecoder.java` before file write operations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apktool

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-19); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
apktool

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-28: 104-1904-2104-2404-28
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-191
Patch1
2026-04-211
Disclosure1
2026-04-241
Disclosure1
2026-04-281
Disclosure1
Full discourse4 posts
  • Connor Tumbleson@iBotPeaches
    Patch

    apktool 3.0.2 is out! - performance boosts - CVE-2026-39973 fix - bug fixes for splits & Meta apks https://apktool.org/blog/apktool-3.0.2

    Post summary

    apktool 3.0.2 release notes highlight a fix for CVE-2026-39973, along with performance improvements and bug fixes.

    01042304
    1.2K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39973: CVE-2026-39973: Arbitrary File Write via Path Traversal in Apktool Apktool versions 3.0.0 and 3.0.1 contain a high-severity path traversal vulnerability due to a security regression in resource decoding. By crafting a malicious APK wit... https://cvereports.com/reports/CVE-2026-39973

    Post summary

    The post publicly discloses a high‑severity path traversal vulnerability in Apktool 3.0.0 and 3.0.1 that allows arbitrary file writes, but it does not provide a PoC, exploit code, or mitigation details.

    0000025
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Apktool Path Traversal to Arbitrary File Write #CVE-2026-39973 (High) https://dailycve.com/apktool-path-traversal-to-arbitrary-file-write-cve-2026-39973-high/

    Post summary

    The message announces CVE-2026-39973, a path-traversal to arbitrary file write flaw in Apktool with high severity, but offers no technical, exploit, or mitigation details.

    0000055
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39973 Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.… https://www.cve.org/CVERecord?id=CVE-2026-39973

    Post summary

    The post announces CVE-2026-39973, a path traversal flaw in Apktool's ResFileDecoder for versions 3.0.0 and 3.0.1, and links to the official CVE record. It offers no proof of concept, exploit, patch, or evidence of active exploitation.

    00000136
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapktoolapktool---

Explore more