VendorsOpensecuritymobile_security_frameworkall versions
Vulnerabilities

Opensecurity Mobile Security Framework

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2024-43399
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Published 2024-08-19 · Analyzed
9.8EPSS 0.010
CVE-2025-31116
Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding
Published 2025-03-31 · Analyzed
9.8EPSS 0.005
CVE-2025-46335
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Published 2025-05-05 · Analyzed
8.6EPSS 0.003
CVE-2025-24805
Local Privilege Escalation in MobSF
Published 2025-02-05 · Analyzed
8.5EPSS 0.004
CVE-2025-24803
Stored Cross-Site Scripting (XSS) in MobSF
Published 2025-02-05 · Analyzed
8.4EPSS 0.004
CVE-2024-53999
Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
Published 2024-12-03 · Analyzed
8.1EPSS 0.005
CVE-2026-24490
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
Published 2026-01-27 · Analyzed
8.1EPSS 0.004
CVE-2022-41547
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.
Published 2022-10-18 · Modified
7.5EPSS 0.013
CVE-2023-42261
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.
Published 2023-09-21 · Modified
7.5EPSS 0.009
CVE-2024-29190
MobSF SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
Published 2024-03-22 · Analyzed
7.5EPSS 0.007
CVE-2024-54000
Mobile Security Framework (MobSF) bypass of SSRF fix
Published 2024-12-03 · Analyzed
7.5EPSS 0.004
CVE-2025-46730
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Published 2025-05-05 · Analyzed
6.8EPSS 0.005
CVE-2025-58162
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
Published 2025-09-02 · Analyzed
6.5EPSS 0.006
CVE-2026-33545
MobSF has SQL Injection in its SQLite Database Viewer Utils
Published 2026-03-26 · Analyzed
6.5EPSS 0.004
CVE-2024-31215
Mobile Security Framework (MobSF) vulnerable to Server-Side Request Forgery (SSRF) in firebase database check
Published 2024-04-04 · Analyzed
6.3EPSS 0.005
CVE-2024-41955
Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect
Published 2024-07-31 · Analyzed
5.4EPSS 0.010
CVE-2025-24804
Partial Denial of Service (DoS) in MobSF
Published 2025-02-05 · Analyzed
4.8EPSS 0.005
CVE-2025-58161
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Published 2025-09-02 · Analyzed
4.3EPSS 0.008