Home

Description

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow. Version 4.3.3 fixes the issue.

PUBLISHED Reserved 2025-04-22 | Published 2025-05-05 | Updated 2025-05-05 | Assigner GitHub_M




HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 4.3.3
affected

References

github.com/...-MobSF/security/advisories/GHSA-mwfg-948f-2cc5

github.com/...ommit/6987a946485a795f4fd38cebdb4860b368a1995d

cve.org (CVE-2025-46335)

nvd.nist.gov (CVE-2025-46335)

Download JSON