Aaptjs Project maintains a narrowly scoped JavaScript-based APK analysis tool that serves security researchers and developers working with Android package inspection. The tool's vulnerability profile centers on a single, focused product where disclosures skew strongly toward critical-severity outcomes, driven by OS command injection weaknesses that arise from insufficient neutralization of special elements in shell commands. Defenders using or deploying this tool should track updates closely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aaptjs Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36381CRITICAL An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-36380CRITICAL An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-36379CRITICAL An issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-36378CRITICAL An issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-36377CRITICAL An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-36376CRITICAL An issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-26707CRITICAL An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code via the filePath parameter. | Oct 31, 2021 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aaptjs Project.
Media articles that mention a CVE ID that affects a product developed by Aaptjs Project — matched by CVE ID, not by vendor name.