VYPR

MobSF

by Mobsf

Source repositories

CVEs (3)

  • CVE-2026-68923MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE tuple, allowing a remote attacker to make…

  • CVE-2026-68922MedAug 18, 2026
    risk 0.29cvss 5.5epss 0.00

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource directory without rejecting traversal or…

  • CVE-2026-68927LowAug 18, 2026
    risk 0.13cvss 3.0epss 0.00

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before appending a separately supplied android:port…