Mobile Security Framework

Opensecurity · 18 CVEs

CVE-2026-33545
MEDIUM

MobSF has SQL Injection in its SQLite Database Viewer Utils

Mar 26, 2026

CVE-2026-24490
HIGH

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

Jan 27, 2026

CVE-2025-58162
MEDIUM

MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

Sep 2, 2025

CVE-2025-58161
LOW

MobSF Path Traversal in GET /download/<filename> using absolute filenames

Sep 2, 2025

CVE-2025-46730
MEDIUM

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

May 5, 2025

CVE-2025-46335
HIGH

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

May 5, 2025

CVE-2025-31116
CRITICAL

Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding

Mar 31, 2025

CVE-2025-24803
HIGH

Stored Cross-Site Scripting (XSS) in MobSF

Feb 5, 2025

CVE-2025-24804
HIGH

Partial Denial of Service (DoS) in MobSF

Feb 5, 2025

CVE-2025-24805
HIGH

Local Privilege Escalation in MobSF

Feb 5, 2025

CVE-2024-53999
MEDIUM

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

Dec 3, 2024

CVE-2024-54000
HIGH

Mobile Security Framework (MobSF) bypass of SSRF fix

Dec 3, 2024

CVE-2024-43399
HIGH

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

Aug 19, 2024

CVE-2024-41955
MEDIUM

Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect

Jul 31, 2024

CVE-2024-31215
MEDIUM

Mobile Security Framework (MobSF) vulnerable to Server-Side Request Forgery (SSRF) in firebase database check

Apr 4, 2024

CVE-2024-29190
HIGH

MobSF SSRF Vulnerability on assetlinks_check(act_name, well_knowns)

Mar 22, 2024

CVE-2023-42261
HIGH

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is t…

Sep 21, 2023

CVE-2022-41547
HIGH

Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability…

Oct 18, 2022

Showing 1 to 18 of 18 CVEs