CVE-2024-24482
NixOS vulnerability analysis and mitigation

Overview

A directory traversal vulnerability was discovered in Apktool versions before 2.9.3 on Windows systems. The vulnerability, identified as CVE-2024-24482, was reported on January 20, 2024. The issue allows attackers to perform directory traversal using '../' and '/..' patterns when processing resource files during APK decoding operations (GitHub Advisory).

Technical details

The vulnerability stems from insufficient path filtering in Apktool's resource handling mechanism. The tool infers resource files' output paths based on their resource names, following the pattern [output-dir]/res/[type]/[resource-name]+[ext of (resource-file)]. The security check implementation failed to properly detect directory traversal attempts on Windows systems, allowing manipulation of resource names to bypass the existing security controls (GitHub Advisory).

Impact

The vulnerability has been assigned a High severity rating with a CVSS score of 7.1. When exploited, it can lead to high impact on both confidentiality and integrity of the affected system, potentially allowing attackers to write files to arbitrary locations on Windows systems (GitHub Advisory).

Mitigation and workarounds

Users are advised to upgrade to Apktool version 2.9.3 or later, which contains the fix for this vulnerability. The patched version implements improved path filtering mechanisms to prevent directory traversal attacks (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management