Junglewise Threat Intelligence

CVE-2026-33989: @mobilenext/mobile-mcp path traversal in file save functions

CVE-2026-33989 · Severity: low · CVSS 3.1 · Published 2026-03-27

Vendors: npm.

Executive brief

The @mobilenext/mobile-mcp npm package is a tool used by AI assistants to control mobile devices and capture screenshots. A path traversal vulnerability in the screenshot and video recording functions allows an attacker to write files to arbitrary locations on the host system. An attacker could exploit this through prompt injection to overwrite critical system files like shell configuration or SSH keys, compromising system integrity and availability.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in src/server.ts where the saveTo parameter of mobile_save_screenshot (lines 584–592) and the output parameter of mobile_start_screen_recording (lines 597–620) are passed directly to fs.writeFileSync() without any validation. While the codebase includes validation functions for other parameters (validatePackageName, validateLocale), no path validation function existed for these file operations. An attacker can exploit this via prompt injection from a malicious website or document to trick the AI into executing tool calls with traversal sequences (e.g., "../../sensitive_file") to write arbitrary files to user home directories or other locations. The attack requires user interaction (the user must interact with the malicious content) but no authentication. Patches were released in version 0.0.49 and later, introducing validateOutputPath and validateFileExtension functions to restrict file writes to allowed extensions and base directories.

Affected products

  • mobilenext mobile-mcp <0.0.49

Timeline

  • 2026-03-27: disclosed: Vulnerability disclosed via GHSA-3p2m-h2v6-g9mx
  • 2026-03-24: patched: Fix released in version 0.0.49 (commit f5e3229)

References

Related threats