---
id: CVE-2024-29190
aliases:
  - GHSA-wfgj-wrgh-h3r3
  - PYSEC-2024-257
  - PYSEC-2026-1677
title: 'SSRF Vulnerability on assetlinks_check(act_name, well_knowns)'
summary: 'SSRF Vulnerability on assetlinks_check(act_name, well_knowns)'
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: mobsfscan
product: mobsfscan
ecosystem: pip
affected:
  - mobsfscan < 0.3.8
patched:
  - mobsfscan 0.3.8
published: '2024-03-22'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-wfgj-wrgh-h3r3'
references:
  - url: >-
      https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-wfgj-wrgh-h3r3
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-29190'
  - url: >-
      https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/5a8eeee73c5f504a6c3abdf2a139a13804efdb77
  - url: >-
      https://github.com/MobSF/mobsfscan/commit/61fd40b477bbf9d204eb8c5a83a86c396d839798
  - url: >-
      https://github.com/MobSF/mobsfscan/commit/cd01b71770a6e56c1c71b0e5f454e7b6c9c64ef4
  - url: >-
      https://drive.google.com/file/d/1nbKMd2sKosbJef5Mh4DxjcHcQ8Hw0BNR/view?usp=share_link
  - url: 'https://github.com/MobSF/Mobile-Security-Framework-MobSF'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/mobsf/PYSEC-2024-257.yaml
tags:
  - osv
  - pip
epss: 0.00718
epssPercentile: 0.51772
ingestedAt: '2026-07-08T18:25:53.620Z'
---

## Overview

### Summary
While examining the "App Link assetlinks.json file could not be found" vulnerability detected by MobSF, we, as the Trendyol Application Security team, noticed that a GET request was sent to the "/.well-known/assetlinks.json" endpoint for all hosts written with "android:host". In the AndroidManifest.xml file.

Since MobSF does not perform any input validation when extracting the hostnames in "android:host", requests can also be sent to local hostnames. This may cause SSRF vulnerability.

### Details
Example <intent-filter structure in AndroidManifest.xml:

```
<intent-filter android:autoVerify="true">
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:host="192.168.1.102/user/delete/1#" android:scheme="http" />
</intent-filter>
```


We defined it as android:host="192.168.1.102/user/delete/1#". Here, the "#" character at the end of the host prevents requests from being sent to the "/.well-known/assetlinks.json" endpoint and ensures that requests are sent to the endpoint before it.


<img width="617" alt="image" src="https://github.com/MobSF/Mobile-Security-Framework-MobSF/assets/150332295/c570cb00-e947-4ad7-af80-26d46c0ad3f7">


### PoC
https://drive.google.com/file/d/1nbKMd2sKosbJef5Mh4DxjcHcQ8Hw0BNR/view?usp=share_link


### Impact
The attacker can cause the server to make a connection to internal-only services within the organization's infrastructure.

## Affected packages

- `mobsfscan < 0.3.8`

## Remediation

Upgrade to a patched release:

- `mobsfscan 0.3.8`
