MobSF 是一款用于移动应用程序安全测试的工具。在版本 4.5.1 之前, 中的 函数使用 Android 清单文件中的 值来构建扫描资源目录下的路径,但未对路径遍历进行拒绝或验证其是否处于预期范围内。这使得经过身份验证的攻击者可以上传一个精心构造的 ZIP 或 APK 文件,读取具有 后缀的服务器文件,并将其以可预测的名称 复制到 目录,然后通过 端点检索该文件。此外,这种行为还可通过 报告字段提供一个文件存在性预言机(file-existence oracle)。该问题已在版本 4.5.1 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MobSF | Mobile-Security-Framework-MobSF | < 4.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MobSF | Mobile-Security-Framework-MobSF | < 4.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68923 | 6.5 MEDIUM | MobSF: CSRF checks not enforced after Django migration |
| CVE-2026-68924 | 4.9 MEDIUM | MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction |
| CVE-2026-68927 | 3.0 LOW | MobSF: SSRF port restriction bypass in assetlinks_check |
No comments yet