A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:android_processing_development_environment_project:android_processing_development_environment:*:*:*:*:*:android:*:*"
],
"vendor_product": "android_processing_development_environment_project:android_processing_development_environment",
"extracted_events": [
{
"fixed": "0.5.2"
}
]
}
]
}{
"cpe": "cpe:2.3:a:android_processing_development_environment_project:android_processing_development_environment:0.5.2:pre1_alpha:*:*:*:android:*:*",
"source": [
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0.5.2-pre1_alpha"
},
{
"last_affected": "0.5.2-pre1_alpha"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"246746123632485132447936165580281533111",
"220234041313732625573971515060463336741",
"229379629916021791409268426342367686473",
"191227737560376208574484726261697587771"
]
},
"signature_version": "v1",
"source": "https://github.com/calsign/apde/commit/c6d64cbe465348c1bfd211122d89e3117afadecf",
"signature_type": "Line",
"target": {
"file": "APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java"
},
"id": "CVE-2020-36628-4e75fc89",
"deprecated": false
},
{
"digest": {
"length": 851.0,
"function_hash": "16989097847878197132046586987275620667"
},
"signature_version": "v1",
"source": "https://github.com/calsign/apde/commit/c6d64cbe465348c1bfd211122d89e3117afadecf",
"signature_type": "Function",
"target": {
"function": "handleExtract",
"file": "APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java"
},
"id": "CVE-2020-36628-edf3680e",
"deprecated": false
}
]
"2026-07-08T20:30:52Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36628.json"