Home

Description

MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1.

PUBLISHED Reserved 2025-08-27 | Published 2025-09-02 | Updated 2025-09-02 | Assigner GitHub_M




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

= 4.4.0
affected

References

github.com/...-MobSF/security/advisories/GHSA-9gh8-9r95-3fc3

github.com/...ommit/7f3bc086c028c1b50889cab8a15f7b59b7abdaf9

github.com/...e-Security-Framework-MobSF/releases/tag/v4.4.1

cve.org (CVE-2025-58162)

nvd.nist.gov (CVE-2025-58162)

Download JSON