---
id: CVE-2025-24805
aliases:
  - GHSA-79f6-p65j-3m2m
  - PYSEC-2026-1667
title: MobSF Local Privilege Escalation
summary: MobSF Local Privilege Escalation
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: mobsf
product: mobsf
ecosystem: pip
affected:
  - mobsf < 4.3.1
patched:
  - mobsf 4.3.1
published: '2025-02-05'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-79f6-p65j-3m2m'
references:
  - url: >-
      https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-79f6-p65j-3m2m
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-24805'
  - url: >-
      https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/05206e72cae35b311615a70e51e1a946955c5e83
  - url: 'https://github.com/MobSF/Mobile-Security-Framework-MobSF'
tags:
  - osv
  - pip
epss: 0.00361
epssPercentile: 0.27271
ingestedAt: '2026-07-08T18:25:46.824Z'
---

## Overview

**Product:** Mobile Security Framework (MobSF)
**Version:** 4.3.0
**CWE-ID:** CWE-269: Improper Privilege Management
**CVSS vector v.4.0:** 7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N)
**CVSS vector v.3.1:** 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
**Description:** MobSF has a functionality of dividing users by roles. This functionality is not efficient, because any registered user can get API Token with all privileges.
**Impact:** Information Disclosure 
**Vulnerable component:** Code output component (`/source_code`)
**Exploitation conditions:** authorized user
**Mitigation:** Remove token output in the returned js-script
**Researcher:** Egor Filatov (Positive Technologies)

## Research 

Researcher discovered zero-day vulnerability «Local Privilege Escalation» in Mobile Security Framework (MobSF).
To reproduce the vulnerability follow the steps below.

•	 A user with minimal privileges is required, so the administrator must create a user account

<img width="215" alt="fig1" src="https://github.com/user-attachments/assets/43e02a50-bdd9-48d9-9194-73946fcc56d9" />

*Figure 1. Registration*

•	Go to static analysis of any application

<img width="1207" alt="fig2" src="https://github.com/user-attachments/assets/9ed141a7-a667-4a96-81fd-d81127874104" />
 
*Figure 2. Static analysis*

•	Go to the code review of the selected application and get a token with all privileges in the response

<img width="1400" alt="fig3" src="https://github.com/user-attachments/assets/bf8b704b-9067-4861-a7d3-05ec119d9a3f" />
 
*Figure 3. Token receiving*

•	This token can be used to retrieve dynamic analysis information that has not been accessed before.

![fig4](https://github.com/user-attachments/assets/fda8436b-de67-45b1-bb21-6cfbc9976f79)
 
*Figure 4. No access demonstration*

<img width="1412" alt="fig5" src="https://github.com/user-attachments/assets/dc8f639f-36b0-47d3-807d-58ae551fcbfc" />
 
*Figure 5. Token usage*

As a result, the user is able to escalate the privileges.


_______________________

### Please, assign all credits to: Egor Filatov (Positive Technologies)

## Affected packages

- `mobsf < 4.3.1`

## Remediation

Upgrade to a patched release:

- `mobsf 4.3.1`
