{"schema_version":1,"title":"mobsf (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in mobsf (PyPI): 0 in the last 7 days and 19 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-68922, was published on 18 August 2026.","url":"https://junglewise.ai/threats/technologies/mobsf","json_url":"https://junglewise.ai/threats/technologies/mobsf.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mobsf","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":22,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":19,"last_365_days":19},"latest":[{"cve":"CVE-2026-68922","cvss":5.5,"epss":0.0046,"slug":"cve-2026-68922-mobsf-path-traversal-in-icon-analysis","title":"MobSF path traversal in icon analysis","severity":"medium","exploited":false,"published_at":"2026-08-18T18:01:26+00:00","url":"https://junglewise.ai/threats/cve-2026-68922-mobsf-path-traversal-in-icon-analysis"},{"cve":"CVE-2026-68923","cvss":6.5,"epss":0.0026,"slug":"cve-2026-68923-mobsf-csrf-protection-bypass-after-django-migration","title":"MobSF CSRF protection bypass after Django migration","severity":"medium","exploited":false,"published_at":"2026-08-18T18:01:13+00:00","url":"https://junglewise.ai/threats/cve-2026-68923-mobsf-csrf-protection-bypass-after-django-migration"},{"cve":"CVE-2026-68927","cvss":3.1,"epss":0.0033,"slug":"cve-2026-68927-mobsf-ssrf-port-restriction-bypass-in-assetlinks-check","title":"MobSF SSRF port restriction bypass in assetlinks_check","severity":"low","exploited":false,"published_at":"2026-08-18T18:01:03+00:00","url":"https://junglewise.ai/threats/cve-2026-68927-mobsf-ssrf-port-restriction-bypass-in-assetlinks-check"},{"cve":"CVE-2026-68924","cvss":4.9,"epss":0.0059,"slug":"cve-2026-68924-mobsf-zip-apk-extraction-denial-of-service-via-per-file-size","title":"MobSF ZIP/APK extraction denial of service via per-file size limit bypass","severity":"medium","exploited":false,"published_at":"2026-08-18T18:00:47+00:00","url":"https://junglewise.ai/threats/cve-2026-68924-mobsf-zip-apk-extraction-denial-of-service-via-per-file-size"},{"cve":"CVE-2026-33545","cvss":3.1,"epss":0.004,"slug":"cve-2026-33545-mobsf-has-sql-injection-in-its-sqlite-database-viewer-utils","title":"PYSEC-2026-2662 - MobSF has SQL Injection in its SQLite Database Viewer Utils","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:44.476212+00:00","url":"https://junglewise.ai/threats/cve-2026-33545-mobsf-has-sql-injection-in-its-sqlite-database-viewer-utils"},{"cve":"CVE-2026-24490","cvss":3.1,"epss":0.0035,"slug":"cve-2026-24490-mobsf-has-stored-xss-via-manifest-analysis-dialer-code-host-field","title":"PYSEC-2026-1668 - MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:20.612144+00:00","url":"https://junglewise.ai/threats/cve-2026-24490-mobsf-has-stored-xss-via-manifest-analysis-dialer-code-host-field"},{"cve":"CVE-2025-58161","cvss":4,"epss":0.0078,"slug":"cve-2025-58161-mobsf-path-traversal-in-get-download-filename-using-absolute","title":"PYSEC-2026-1672 - MobSF Path Traversal in GET /download/<filename> using absolute filenames","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:03.065548+00:00","url":"https://junglewise.ai/threats/cve-2025-58161-mobsf-path-traversal-in-get-download-filename-using-absolute"},{"cve":"CVE-2025-58162","cvss":3.1,"epss":0.006,"slug":"cve-2025-58162-mobsf-vulnerable-to-arbitrary-file-write-ar-slip-via-absolute","title":"PYSEC-2026-1670 - MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:02.996143+00:00","url":"https://junglewise.ai/threats/cve-2025-58162-mobsf-vulnerable-to-arbitrary-file-write-ar-slip-via-absolute"},{"cve":"CVE-2025-46730","cvss":3.1,"epss":0.0048,"slug":"cve-2025-46730-mobile-security-framework-mobsf-allows-web-server-resource","title":"PYSEC-2026-1671 - Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:51.843471+00:00","url":"https://junglewise.ai/threats/cve-2025-46730-mobile-security-framework-mobsf-allows-web-server-resource"},{"cve":"CVE-2025-46335","cvss":4,"epss":0.0031,"slug":"cve-2025-46335-mobile-security-framework-mobsf-allows-stored-cross-site","title":"PYSEC-2026-1675 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:51.772644+00:00","url":"https://junglewise.ai/threats/cve-2025-46335-mobile-security-framework-mobsf-allows-stored-cross-site"},{"cve":"CVE-2025-24805","cvss":3.1,"epss":0.0036,"slug":"cve-2025-24805-mobsf-local-privilege-escalation","title":"PYSEC-2026-1667 - MobSF Local Privilege Escalation","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:49.397304+00:00","url":"https://junglewise.ai/threats/cve-2025-24805-mobsf-local-privilege-escalation"},{"cve":"CVE-2025-24804","cvss":3.1,"epss":0.0046,"slug":"cve-2025-24804-mobsf-partial-denial-of-service-dos","title":"PYSEC-2026-1674 - MobSF Partial Denial of Service (DoS)","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:49.330046+00:00","url":"https://junglewise.ai/threats/cve-2025-24804-mobsf-partial-denial-of-service-dos"},{"cve":"CVE-2025-24803","cvss":3.1,"epss":0.0039,"slug":"cve-2025-24803-mobsf-stored-cross-site-scripting-xss","title":"PYSEC-2026-1673 - MobSF Stored Cross-Site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:49.259197+00:00","url":"https://junglewise.ai/threats/cve-2025-24803-mobsf-stored-cross-site-scripting-xss"},{"cve":"CVE-2024-53999","cvss":3.1,"epss":0.0052,"slug":"cve-2024-53999-mobile-security-framework-mobsf-stored-cross-site-scripting","title":"PYSEC-2026-1666 - Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in \"Diff or Compare\" Functionality","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:46.751043+00:00","url":"https://junglewise.ai/threats/cve-2024-53999-mobile-security-framework-mobsf-stored-cross-site-scripting"},{"cve":"CVE-2024-43399","cvss":3.1,"epss":0.0096,"slug":"cve-2024-43399-mobile-security-framework-mobsf-has-a-zip-slip-vulnerability-in-a","title":"PYSEC-2026-1665 - Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:38.904256+00:00","url":"https://junglewise.ai/threats/cve-2024-43399-mobile-security-framework-mobsf-has-a-zip-slip-vulnerability-in-a"},{"cve":"CVE-2024-41955","cvss":3.1,"epss":0.01,"slug":"cve-2024-41955-mobsf-vulnerable-to-open-redirect-in-login-redirect","title":"PYSEC-2026-1669 - MobSF vulnerable to Open Redirect in Login Redirect","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:38.154317+00:00","url":"https://junglewise.ai/threats/cve-2024-41955-mobsf-vulnerable-to-open-redirect-in-login-redirect"},{"cve":"CVE-2024-31215","cvss":3.1,"epss":0.0051,"slug":"cve-2024-31215-mobile-security-framework-mobsf-vulnerable-to-ssrf-in-firebase","title":"PYSEC-2026-1676 - Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:37.418995+00:00","url":"https://junglewise.ai/threats/cve-2024-31215-mobile-security-framework-mobsf-vulnerable-to-ssrf-in-firebase"},{"cve":"CVE-2024-29190","cvss":3.1,"epss":0.0072,"slug":"cve-2024-29190-ssrf-vulnerability-on-assetlinks-check-act-name-well-knowns","title":"PYSEC-2026-1677 - SSRF Vulnerability on assetlinks_check(act_name, well_knowns)","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:36.23307+00:00","url":"https://junglewise.ai/threats/cve-2024-29190-ssrf-vulnerability-on-assetlinks-check-act-name-well-knowns"},{"cve":"CVE-2022-41547","cvss":3.1,"epss":0.0133,"slug":"cve-2022-41547-mobsf-allows-attackers-to-read-arbitrary-files-via-a-crafted-http","title":"PYSEC-2026-848 - MobSF allows attackers to read arbitrary files via a crafted HTTP request","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:22.664475+00:00","url":"https://junglewise.ai/threats/cve-2022-41547-mobsf-allows-attackers-to-read-arbitrary-files-via-a-crafted-http"},{"cve":"CVE-2025-31116","cvss":3.1,"epss":0.0047,"slug":"cve-2025-31116-mobile-security-framework-mobsf-has-a-ssrf-vulnerability-fix","title":"PYSEC-2025-48 - Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dyna","severity":"low","exploited":false,"published_at":"2025-03-31T17:15:42+00:00","url":"https://junglewise.ai/threats/cve-2025-31116-mobile-security-framework-mobsf-has-a-ssrf-vulnerability-fix"},{"cve":"CVE-2024-54000","cvss":3.1,"epss":0.0041,"slug":"cve-2024-54000-mobsf-vulnerability-allows-ssrf-due-to-the-allow-redirects-true","title":"PYSEC-2024-256 - Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dyna","severity":"low","exploited":false,"published_at":"2024-12-03T16:15:24+00:00","url":"https://junglewise.ai/threats/cve-2024-54000-mobsf-vulnerability-allows-ssrf-due-to-the-allow-redirects-true"},{"cve":"CVE-2023-42261","cvss":3.1,"epss":0.0086,"slug":"cve-2023-42261-withdrawn-advisory-mobile-security-framework-mobsf-vulnerable-to","title":"PYSEC-2023-310 - Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is","severity":"low","exploited":false,"published_at":"2023-09-21T22:15:11+00:00","url":"https://junglewise.ai/threats/cve-2023-42261-withdrawn-advisory-mobile-security-framework-mobsf-vulnerable-to"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":14},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"mobsf (PyPI)","slug":"mobsf","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Python framework for mobile application security testing and vulnerability assessment.","url":"https://junglewise.ai/threats/technologies/mobsf"},"most_severe":[{"cve":"CVE-2026-68923","cvss":6.5,"epss":0.0026,"slug":"cve-2026-68923-mobsf-csrf-protection-bypass-after-django-migration","title":"MobSF CSRF protection bypass after Django migration","severity":"medium","exploited":false,"published_at":"2026-08-18T18:01:13+00:00","url":"https://junglewise.ai/threats/cve-2026-68923-mobsf-csrf-protection-bypass-after-django-migration"},{"cve":"CVE-2026-68922","cvss":5.5,"epss":0.0046,"slug":"cve-2026-68922-mobsf-path-traversal-in-icon-analysis","title":"MobSF path traversal in icon analysis","severity":"medium","exploited":false,"published_at":"2026-08-18T18:01:26+00:00","url":"https://junglewise.ai/threats/cve-2026-68922-mobsf-path-traversal-in-icon-analysis"},{"cve":"CVE-2026-68924","cvss":4.9,"epss":0.0059,"slug":"cve-2026-68924-mobsf-zip-apk-extraction-denial-of-service-via-per-file-size","title":"MobSF ZIP/APK extraction denial of service via per-file size limit bypass","severity":"medium","exploited":false,"published_at":"2026-08-18T18:00:47+00:00","url":"https://junglewise.ai/threats/cve-2026-68924-mobsf-zip-apk-extraction-denial-of-service-via-per-file-size"},{"cve":"CVE-2025-58161","cvss":4,"epss":0.0078,"slug":"cve-2025-58161-mobsf-path-traversal-in-get-download-filename-using-absolute","title":"PYSEC-2026-1672 - MobSF Path Traversal in GET /download/<filename> using absolute filenames","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:03.065548+00:00","url":"https://junglewise.ai/threats/cve-2025-58161-mobsf-path-traversal-in-get-download-filename-using-absolute"},{"cve":"CVE-2025-46335","cvss":4,"epss":0.0031,"slug":"cve-2025-46335-mobile-security-framework-mobsf-allows-stored-cross-site","title":"PYSEC-2026-1675 - Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:51.772644+00:00","url":"https://junglewise.ai/threats/cve-2025-46335-mobile-security-framework-mobsf-allows-stored-cross-site"},{"cve":"CVE-2022-41547","cvss":3.1,"epss":0.0133,"slug":"cve-2022-41547-mobsf-allows-attackers-to-read-arbitrary-files-via-a-crafted-http","title":"PYSEC-2026-848 - MobSF allows attackers to read arbitrary files via a crafted HTTP request","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:22.664475+00:00","url":"https://junglewise.ai/threats/cve-2022-41547-mobsf-allows-attackers-to-read-arbitrary-files-via-a-crafted-http"},{"cve":"CVE-2024-41955","cvss":3.1,"epss":0.01,"slug":"cve-2024-41955-mobsf-vulnerable-to-open-redirect-in-login-redirect","title":"PYSEC-2026-1669 - MobSF vulnerable to Open Redirect in Login Redirect","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:38.154317+00:00","url":"https://junglewise.ai/threats/cve-2024-41955-mobsf-vulnerable-to-open-redirect-in-login-redirect"},{"cve":"CVE-2024-43399","cvss":3.1,"epss":0.0096,"slug":"cve-2024-43399-mobile-security-framework-mobsf-has-a-zip-slip-vulnerability-in-a","title":"PYSEC-2026-1665 - Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:38.904256+00:00","url":"https://junglewise.ai/threats/cve-2024-43399-mobile-security-framework-mobsf-has-a-zip-slip-vulnerability-in-a"},{"cve":"CVE-2023-42261","cvss":3.1,"epss":0.0086,"slug":"cve-2023-42261-withdrawn-advisory-mobile-security-framework-mobsf-vulnerable-to","title":"PYSEC-2023-310 - Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is","severity":"low","exploited":false,"published_at":"2023-09-21T22:15:11+00:00","url":"https://junglewise.ai/threats/cve-2023-42261-withdrawn-advisory-mobile-security-framework-mobsf-vulnerable-to"},{"cve":"CVE-2024-29190","cvss":3.1,"epss":0.0072,"slug":"cve-2024-29190-ssrf-vulnerability-on-assetlinks-check-act-name-well-knowns","title":"PYSEC-2026-1677 - SSRF Vulnerability on assetlinks_check(act_name, well_knowns)","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:36.23307+00:00","url":"https://junglewise.ai/threats/cve-2024-29190-ssrf-vulnerability-on-assetlinks-check-act-name-well-knowns"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}