CVE-2024-31215Medium· 6.3▾ SunlitMobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.5%
Last analysed / modified upstream
What kind of vulnerability is it? Who is impacted? SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When malicious app is uploaded to Static analyzer, it is possible to make internal requests.
Credits: Oleg Surnin (Positive Technologies).
Has the problem been patched? What versions should users upgrade to? v3.9.8 and above
Is there a way for users to fix or remediate the vulnerability without upgrading? Code level patch
Are there any links users can visit to find out more? https://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/2373
mobsf < 3.9.8Upgrade to a patched release:
mobsf 3.9.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33545Medium· 5.3MobSF has SQL Injection in its SQLite Database Viewer Utils
CVE-2025-46335MediumMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
CVE-2025-24804Medium· 6.5MobSF Partial Denial of Service (DoS)
CVE-2022-41547High· 7.5MobSF allows attackers to read arbitrary files via a crafted HTTP request
CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)
CVE-2025-58161LowMobSF Path Traversal in GET /download/<filename> using absolute filenames