Technology · PyPI
mobsf (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in mobsf (PyPI): 0 in the last 7 days and 19 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-68922, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 0
- Exploited in the wild
- 0
About mobsf (PyPI)
Python framework for mobile application security testing and vulnerability assessment.
Latest mobsf (PyPI) vulnerabilities
- CVE-2026-68922: MobSF path traversal in icon analysismediumCVSS 5.5EPSS 0.5%
- CVE-2026-68923: MobSF CSRF protection bypass after Django migrationmediumCVSS 6.5EPSS 0.3%
- CVE-2026-68927: MobSF SSRF port restriction bypass in assetlinks_checklowCVSS 3.1EPSS 0.3%
- CVE-2026-68924: MobSF ZIP/APK extraction denial of service via per-file size limit bypassmediumCVSS 4.9EPSS 0.6%
- CVE-2026-33545: PYSEC-2026-2662 - MobSF has SQL Injection in its SQLite Database Viewer UtilslowCVSS 3.1EPSS 0.4%
- CVE-2026-24490: PYSEC-2026-1668 - MobSF has Stored XSS via Manifest Analysis - Dialer Code Host FieldlowCVSS 3.1EPSS 0.4%
- CVE-2025-58161: PYSEC-2026-1672 - MobSF Path Traversal in GET /download/<filename> using absolute filenamesmediumCVSS 4EPSS 0.8%
- CVE-2025-58162: PYSEC-2026-1670 - MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a ExtractionlowCVSS 3.1EPSS 0.6%
- CVE-2025-46730: PYSEC-2026-1671 - Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death AttacklowCVSS 3.1EPSS 0.5%
- CVE-2025-46335: PYSEC-2026-1675 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon UploadmediumCVSS 4EPSS 0.3%
- CVE-2025-24805: PYSEC-2026-1667 - MobSF Local Privilege EscalationlowCVSS 3.1EPSS 0.4%
- CVE-2025-24804: PYSEC-2026-1674 - MobSF Partial Denial of Service (DoS)lowCVSS 3.1EPSS 0.5%
- CVE-2025-24803: PYSEC-2026-1673 - MobSF Stored Cross-Site Scripting (XSS)lowCVSS 3.1EPSS 0.4%
- CVE-2024-53999: PYSEC-2026-1666 - Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare"…lowCVSS 3.1EPSS 0.5%
- CVE-2024-43399: PYSEC-2026-1665 - Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library FileslowCVSS 3.1EPSS 1.0%
- CVE-2024-41955: PYSEC-2026-1669 - MobSF vulnerable to Open Redirect in Login RedirectlowCVSS 3.1EPSS 1.0%
- CVE-2024-31215: PYSEC-2026-1676 - Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database checklowCVSS 3.1EPSS 0.5%
- CVE-2024-29190: PYSEC-2026-1677 - SSRF Vulnerability on assetlinks_check(act_name, well_knowns)lowCVSS 3.1EPSS 0.7%
- CVE-2022-41547: PYSEC-2026-848 - MobSF allows attackers to read arbitrary files via a crafted HTTP requestlowCVSS 3.1EPSS 1.3%
- CVE-2025-31116: PYSEC-2025-48 - Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework…lowCVSS 3.1EPSS 0.5%
- CVE-2024-54000: PYSEC-2024-256 - Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework…lowCVSS 3.1EPSS 0.4%
- CVE-2023-42261: PYSEC-2023-310 - Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's…lowCVSS 3.1EPSS 0.9%
Most severe mobsf (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-68923: MobSF CSRF protection bypass after Django migrationmediumCVSS 6.5EPSS 0.3%
- CVE-2026-68922: MobSF path traversal in icon analysismediumCVSS 5.5EPSS 0.5%
- CVE-2026-68924: MobSF ZIP/APK extraction denial of service via per-file size limit bypassmediumCVSS 4.9EPSS 0.6%
- CVE-2025-58161: PYSEC-2026-1672 - MobSF Path Traversal in GET /download/<filename> using absolute filenamesmediumCVSS 4EPSS 0.8%
- CVE-2025-46335: PYSEC-2026-1675 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon UploadmediumCVSS 4EPSS 0.3%
- CVE-2022-41547: PYSEC-2026-848 - MobSF allows attackers to read arbitrary files via a crafted HTTP requestlowCVSS 3.1EPSS 1.3%
- CVE-2024-41955: PYSEC-2026-1669 - MobSF vulnerable to Open Redirect in Login RedirectlowCVSS 3.1EPSS 1.0%
- CVE-2024-43399: PYSEC-2026-1665 - Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library FileslowCVSS 3.1EPSS 1.0%
- CVE-2023-42261: PYSEC-2023-310 - Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's…lowCVSS 3.1EPSS 0.9%
- CVE-2024-29190: PYSEC-2026-1677 - SSRF Vulnerability on assetlinks_check(act_name, well_knowns)lowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 14 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 4 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mobsf.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "mobsf (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/mobsf, 27 September 2026.