PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35394 mobile-next CVE debrief

CVE-2026-35394 is a high-severity vulnerability in the Mobile Next MCP server for mobile development and automation. The mobile_open_url tool passes user-supplied URLs directly to Android's intent system without scheme validation, allowing execution of arbitrary Android intents. This includes USSD codes, phone calls, SMS messages, and content provider access. The vulnerability is fixed in version 0.0.50. Organizations should prioritize patching to prevent potential exploitation and data breaches.

Vendor
mobile-next
Product
mobile-mcp
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Organizations using Mobile Next MCP server for mobile development and automation should prioritize patching to version 0.0.50 or later. Developers and security teams responsible for mobile application security and Android intent system interactions should be aware of this vulnerability and take necessary precautions.

Technical summary

The mobile_open_url tool in Mobile Next MCP server prior to 0.0.50 passes user-supplied URLs directly to Android's intent system without any scheme validation. This allows for the execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. The vulnerability is addressed in version 0.0.50. Affected systems should prioritize patching to prevent exploitation.

Defensive priority

High priority should be given to patching Mobile Next MCP server to version 0.0.50 or later. Implementing compensating controls, such as URL validation and intent filtering, may be necessary until patching can be performed.

Recommended defensive actions

  • Patch Mobile Next MCP server to version 0.0.50 or later
  • Implement URL validation and intent filtering as compensating controls
  • Monitor for suspicious activity related to Android intent execution
  • Review and update mobile application security policies and procedures
  • Conduct a thorough review of exposed systems and assets
  • Verify the effectiveness of compensating controls
  • Track and document remediation progress and exceptions

Evidence notes

The CVE record was published on 2026-04-06T21:16:21.300Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability is described in the CVE record and NVD detail pages. Evidence of exploitation is not currently available, but defenders should verify affected scope and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T21:16:21.300Z and has not been modified since then. The NVD entry is currently Analyzed.