{"id":"CVE-2024-41955","aliases":["GHSA-8m9j-2f32-2vx4","PYSEC-2026-1669"],"title":"MobSF vulnerable to Open Redirect in Login Redirect","summary":"MobSF vulnerable to Open Redirect in Login Redirect","severity":"medium","cvss":5.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N","vendor":"mobsf","product":"mobsf","ecosystem":"pip","affected":["mobsf < 4.0.5"],"patched":["mobsf 4.0.5"],"published":"2024-07-31","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8m9j-2f32-2vx4","references":[{"url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-8m9j-2f32-2vx4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41955"},{"url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/fdaad81314f393d324c1ede79627e9d47986c8c8"},{"url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF"}],"tags":["osv","pip","exploit-available"],"epss":0.01,"epssPercentile":0.61335,"ingestedAt":"2026-07-08T18:25:47.516Z","exploits":{"nuclei":["CVE-2024-41955"],"checkedAt":"2026-09-23T07:13:29.952Z"},"exploitAvailable":true,"slug":"CVE-2024-41955","body":"## Overview\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nAn open redirect vulnerability exist in MobSF authentication view. \n\nPoC\n1. Go to http://127.0.0.1:8000/login/?next=//afine.com in a web browser.\n2. Enter credentials and press \"Sign In\".\n3. You will be redirected to [afine.com](http://afine.com/)\n\nUsers who are not using authentication are not impacted.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nUpdate to MobSF v4.0.5\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nDisable Authentication\n\n### References\n_Are there any links users can visit to find out more?_\nFix: https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/fdaad81314f393d324c1ede79627e9d47986c8c8\n\n### Reporter\nMarcin Węgłowski (AFINE Team)\n\n\n## Affected packages\n\n- `mobsf < 4.0.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `mobsf 4.0.5`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":28.6,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4729,"id":"CVE-2024-41955","ts":1788887202640,"field":"exploit_available","old":"false","new":"true"},{"seq":3612,"id":"CVE-2024-41955","ts":1788886318777,"field":"exploit_available","old":"true","new":"false"},{"seq":2466,"id":"CVE-2024-41955","ts":1788882987363,"field":"exploit_available","old":"false","new":"true"},{"seq":1495,"id":"CVE-2024-41955","ts":1788882400850,"field":"exploit_available","old":"true","new":"false"},{"seq":609,"id":"CVE-2024-41955","ts":1788881837518,"field":"exploit_available","old":"false","new":"true"}]}