CVE-2026-68927Low· 3.0▾ SunlitMobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before ap…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 16.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before appending a separately supplied android:port to the URL fetched by _check_url, allowing an authenticated user to upload a crafted APK that makes requests to an attacker-selected nonstandard port at /.well-known/assetlinks.json. With an attacker-controlled hostname and DNS rebinding between validation and the requests.get connection, the request can reach an internal service, although redirects remain disabled and the path is fixed. This issue is fixed in version 4.5.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
mobsf < 4.5.1Patched in:
mobsf 4.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68924Medium· 4.9MobSF is a mobile application security testing tool used
CVE-2026-68923Medium· 6.5MobSF is a mobile application security testing tool used
CVE-2026-68922Medium· 5.5MobSF is a mobile application security testing tool used
CVE-2026-33545Medium· 5.3MobSF has SQL Injection in its SQLite Database Viewer Utils
CVE-2024-31215Medium· 6.3Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
CVE-2025-46335MediumMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload