CVE-2024-43399

HIGH

Mobile Security Framework < 4.0.7 - Path Traversal via Static Libraries Extraction

Title source: llm
STIX 2.1

Description

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent Zip Slip attacks is improperly implemented. Since the implemented measure can be bypassed, the vulnerability allows an attacker to extract files to any desired location within the server running MobSF. This vulnerability is fixed in 4.0.7.

Scores

CVSS v3 8.0
EPSS 0.0090
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-23
Status published
Products (2)
opensecurity/mobile_security_framework < 4.0.7
pypi/mobsf 0 - 4.0.7PyPI
Published Aug 19, 2024
Tracked Since Feb 18, 2026