CVE-2025-31116

MEDIUM

Opensecurity Mobile Security Framework < 4.3.2 - SSRF

Title source: rule
STIX 2.1

Description

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.

Scores

CVSS v3 4.4
EPSS 0.0031
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
opensecurity/mobile_security_framework < 4.3.2
pypi/mobsf 0 - 4.3.2PyPI
Published Mar 31, 2025
Tracked Since Feb 18, 2026