PatchSiren cyber security CVE debrief
CVE-2026-35394 mobile-next CVE debrief
CVE-2026-35394 is a high-severity vulnerability in the Mobile Next MCP server for mobile development and automation. The mobile_open_url tool passes user-supplied URLs directly to Android's intent system without scheme validation, allowing execution of arbitrary Android intents. This includes USSD codes, phone calls, SMS messages, and content provider access. The vulnerability is fixed in version 0.0.50. Organizations should prioritize patching to prevent potential exploitation and data breaches.
- Vendor
- mobile-next
- Product
- mobile-mcp
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Organizations using Mobile Next MCP server for mobile development and automation should prioritize patching to version 0.0.50 or later. Developers and security teams responsible for mobile application security and Android intent system interactions should be aware of this vulnerability and take necessary precautions.
Technical summary
The mobile_open_url tool in Mobile Next MCP server prior to 0.0.50 passes user-supplied URLs directly to Android's intent system without any scheme validation. This allows for the execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. The vulnerability is addressed in version 0.0.50. Affected systems should prioritize patching to prevent exploitation.
Defensive priority
High priority should be given to patching Mobile Next MCP server to version 0.0.50 or later. Implementing compensating controls, such as URL validation and intent filtering, may be necessary until patching can be performed.
Recommended defensive actions
- Patch Mobile Next MCP server to version 0.0.50 or later
- Implement URL validation and intent filtering as compensating controls
- Monitor for suspicious activity related to Android intent execution
- Review and update mobile application security policies and procedures
- Conduct a thorough review of exposed systems and assets
- Verify the effectiveness of compensating controls
- Track and document remediation progress and exceptions
Evidence notes
The CVE record was published on 2026-04-06T21:16:21.300Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability is described in the CVE record and NVD detail pages. Evidence of exploitation is not currently available, but defenders should verify affected scope and vendor guidance.
Official resources
-
CVE-2026-35394 CVE record
CVE.org
-
CVE-2026-35394 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Mitigation, Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T21:16:21.300Z and has not been modified since then. The NVD entry is currently Analyzed.