MobSF 是一个用于移动应用安全测试的工具。在 4.5.1 版本之前, 中的解压缩功能在遇到超过 限制的归档成员时,虽然会记录一条日志说明该成员被跳过,但并未继续处理后续的归档成员。因此,经过身份验证的用户可以上传一个构造好的 ZIP 或 APK 文件,其中包含一个超大成员。在未达到 总大小限制的情况下,该超大成员仍会被解压到磁盘,可能导致磁盘空间耗尽,从而阻止进一步的扫描操作。此问题已在 4.5.1 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MobSF | Mobile-Security-Framework-MobSF | < 4.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MobSF | Mobile-Security-Framework-MobSF | < 4.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68923 | 6.5 MEDIUM | MobSF: CSRF checks not enforced after Django migration |
| CVE-2026-68922 | 5.5 MEDIUM | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads |
| CVE-2026-68927 | 3.0 LOW | MobSF: SSRF port restriction bypass in assetlinks_check |
No comments yet