CVE-2024-43399

HIGH

Opensecurity Mobile Security Framework < 4.0.7 - Path Traversal

Title source: rule
STIX 2.1

Description

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent Zip Slip attacks is improperly implemented. Since the implemented measure can be bypassed, the vulnerability allows an attacker to extract files to any desired location within the server running MobSF. This vulnerability is fixed in 4.0.7.

Scores

CVSS v3 8.0
EPSS 0.0043
EPSS Percentile 62.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-23
Status published
Products (2)
opensecurity/mobile_security_framework < 4.0.7
pypi/mobsf 0 - 4.0.7PyPI
Published Aug 19, 2024
Tracked Since Feb 18, 2026