Description
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.
References (2)
Core 2
Core References
Patch, Third Party Advisory
https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/b9cdd1f52bdf127cf33bb1be369e374a2855f8e6#diff-69d2e38f6bba208c333da6a09a83ca65056fcb60f4e10d23f67c01bcc1ffb58c
Exploit, Third Party Advisory
https://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/166
Scores
CVSS v3
7.5
EPSS
0.0237
EPSS Percentile
85.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-98
Status
published
Products (2)
opensecurity/mobile_security_framework
< 0.9.2
pypi/mobsf
0 - 0.9.3PyPI
Published
Oct 18, 2022
Tracked Since
Feb 18, 2026