Opensecurity
Opensecurity Mobile Security Framework: vulnerabilidades y CVE
Opensecurity Mobile Security Framework tiene 18 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33545 | Media (6.5) | 0.40% | — | 26 mar 2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries… |
| CVE-2026-24490 | Media (4.8) | 0.35% | — | 27 ene 2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript… |
| CVE-2025-58162 | Media (6.5) | 0.60% | — | 2 sept 2025 | MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF… |
| CVE-2025-58161 | Baja (1.3) | 0.78% | — | 2 sept 2025 | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside… |
| CVE-2025-46730 | Media (6.5) | 0.48% | — | 5 may 2025 | MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web… |
| CVE-2025-46335 | Alta (8.6) | 0.30% | — | 5 may 2025 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to… |
| CVE-2025-31116 | Crítica (9.8) | 0.47% | — | 31 mar 2025 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses… |
| CVE-2025-24805 | Alta (8.5) | 0.36% | — | 5 feb 2025 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to… |
| CVE-2025-24804 | Media (4.8) | 0.46% | — | 5 feb 2025 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's,… |
| CVE-2025-24803 | Alta (8.4) | 0.39% | — | 5 feb 2025 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's,… |
| CVE-2024-54000 | Alta (7.5) | 0.41% | — | 3 dic 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the… |
| CVE-2024-53999 | Media (5.4) | 0.52% | — | 3 dic 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the… |
| CVE-2024-43399 | Crítica (9.8) | 0.96% | — | 19 ago 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis… |
| CVE-2024-41955 | Media (5.4) | 1.0% | — | 31 jul 2024 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5. |
| CVE-2024-31215 | Media (4.3) | 0.51% | — | 4 abr 2024 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to… |
| CVE-2024-29190 | Alta (7.5) | 0.72% | — | 22 mar 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and prior, MobSF does not perform any input… |
| CVE-2023-42261 | Alta (7.5) | 0.86% | — | 21 sept 2023 | Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an… |
| CVE-2022-41547 | Alta (7.5) | 1.3% | — | 18 oct 2022 | Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files… |