PT-2026-31441 · Tophat · Tophat

CVE-2026-39862

·

Published

2026-04-08

·

Updated

2026-04-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tophat versions prior to 2.5.1
Description Tophat, a mobile applications testing harness, is susceptible to remote code execution through specially crafted tophat:// or http://localhost:29070 URLs. The arguments query parameter is processed without proper sanitization, leading to execution of arbitrary commands via /bin/bash -c on a developer's macOS workstation. Developers with Tophat installed are affected. No confirmation dialog is displayed for previously trusted build hosts, and attacker commands execute with the user's permissions.
Recommendations Update to version 2.5.1 or later.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39862
GHSA-8X8G-6RV5-MGG2

Affected Products

Tophat