mobsf has 18 CVEs on record between 2022 and 2026. 4 were published in the last 90 days. The busiest recent month was August 2026 with 4. The median CVSS is 6.5 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-24490High· 8.1MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field45CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)45CVE-2024-43399High· 8.0Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files44CVE-2022-41547High· 7.5MobSF allows attackers to read arbitrary files via a crafted HTTP request42CVE-2024-41955Medium· 5.2MobSF vulnerable to Open Redirect in Login Redirect41
mobsf vulnerabilities
CVEs affecting mobsf, newest first. Open any entry for full detail, references, and exploit status.
18 CVEsRSS
CVE-2026-68924Medium· 4.9MobSF is a mobile application security testing tool used
MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but do…
CVE-2026-68927Low· 3.0MobSF is a mobile application security testing tool used
MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before ap…
CVE-2026-68923Medium· 6.5MobSF is a mobile application security testing tool used
MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE …
CVE-2026-68922Medium· 5.5MobSF is a mobile application security testing tool used
MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource d…
CVE-2026-33545Medium· 5.3MobSF has SQL Injection in its SQLite Database Viewer Utils
MobSF has SQL Injection in its SQLite Database Viewer Utils
CVE-2026-24490High· 8.1MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
CVE-2025-58161LowMobSF Path Traversal in GET /download/<filename> using absolute filenames
MobSF Path Traversal in GET /download/<filename> using absolute filenames
CVE-2025-58162Medium· 6.5MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
CVE-2025-46335MediumMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
CVE-2025-46730Medium· 6.8Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
CVE-2025-24804Medium· 6.5MobSF Partial Denial of Service (DoS)
MobSF Partial Denial of Service (DoS)
CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)
MobSF Stored Cross-Site Scripting (XSS)
CVE-2025-24805Medium· 6.5MobSF Local Privilege Escalation
MobSF Local Privilege Escalation
CVE-2024-53999Medium· 6.1Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
CVE-2024-43399High· 8.0Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
CVE-2024-41955Medium· 5.2PoCMobSF vulnerable to Open Redirect in Login Redirect
MobSF vulnerable to Open Redirect in Login Redirect
CVE-2024-31215Medium· 6.3Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
CVE-2022-41547High· 7.5MobSF allows attackers to read arbitrary files via a crafted HTTP request
MobSF allows attackers to read arbitrary files via a crafted HTTP request