Path traversal in Ghidra - #VU144378
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to path traversal in AndroidProjectCreator \"Export to Eclipse Project\" action when processing a crafted .apk file. A remote attacker can trick the victim into exporting a crafted APK to execute arbitrary code.
User interaction is required to open an attacker-supplied APK and trigger the export action. The issue can also be abused to overwrite arbitrary user-writable files outside the selected output directory.