Mobile Security Framework
Opensecurity · 18 CVEs
MobSF has SQL Injection in its SQLite Database Viewer Utils
Mar 26, 2026
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
Jan 27, 2026
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
Sep 2, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Sep 2, 2025
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
May 5, 2025
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
May 5, 2025
Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding
Mar 31, 2025
Stored Cross-Site Scripting (XSS) in MobSF
Feb 5, 2025
Partial Denial of Service (DoS) in MobSF
Feb 5, 2025
Local Privilege Escalation in MobSF
Feb 5, 2025
Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
Dec 3, 2024
Mobile Security Framework (MobSF) bypass of SSRF fix
Dec 3, 2024
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Aug 19, 2024
Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect
Jul 31, 2024
Mobile Security Framework (MobSF) vulnerable to Server-Side Request Forgery (SSRF) in firebase database check
Apr 4, 2024
MobSF SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
Mar 22, 2024
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is t…
Sep 21, 2023
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability…
Oct 18, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-33545 | MobSF has SQL Injection in its SQLite Database Viewer Utils | MEDIUM | 0.40% | Mar 26, 2026 |
| CVE-2026-24490 | MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field | HIGH | 0.35% | Jan 27, 2026 |
| CVE-2025-58162 | MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction | MEDIUM | 0.60% | Sep 2, 2025 |
| CVE-2025-58161 | MobSF Path Traversal in GET /download/<filename> using absolute filenames | LOW | 0.78% | Sep 2, 2025 |
| CVE-2025-46730 | Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack | MEDIUM | 0.50% | May 5, 2025 |
| CVE-2025-46335 | Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload | HIGH | 0.32% | May 5, 2025 |
| CVE-2025-31116 | Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding | CRITICAL | 0.47% | Mar 31, 2025 |
| CVE-2025-24803 | Stored Cross-Site Scripting (XSS) in MobSF | HIGH | 0.39% | Feb 5, 2025 |
| CVE-2025-24804 | Partial Denial of Service (DoS) in MobSF | HIGH | 0.46% | Feb 5, 2025 |
| CVE-2025-24805 | Local Privilege Escalation in MobSF | HIGH | 0.36% | Feb 5, 2025 |
| CVE-2024-53999 | Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality | MEDIUM | 0.52% | Dec 3, 2024 |
| CVE-2024-54000 | Mobile Security Framework (MobSF) bypass of SSRF fix | HIGH | 0.41% | Dec 3, 2024 |
| CVE-2024-43399 | Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files | HIGH | 0.96% | Aug 19, 2024 |
| CVE-2024-41955 | Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect | MEDIUM | 1.00% | Jul 31, 2024 |
| CVE-2024-31215 | Mobile Security Framework (MobSF) vulnerable to Server-Side Request Forgery (SSRF) in firebase database check | MEDIUM | 0.51% | Apr 4, 2024 |
| CVE-2024-29190 | MobSF SSRF Vulnerability on assetlinks_check(act_name, well_knowns) | HIGH | 0.72% | Mar 22, 2024 |
| CVE-2023-42261 | Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not… | HIGH | 0.86% | Sep 21, 2023 |
| CVE-2022-41547 | Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script.… | HIGH | 1.33% | Oct 18, 2022 |
Showing 1 to 18 of 18 CVEs