HIGH
mobile-next
CVE published 2026-04-06
CVE-2026-35394
CVE-2026-35394 is a high-severity vulnerability in the Mobile Next MCP server for mobile development and automation. The mobile_open_url tool passes user-supplied URLs directly to Android's intent system without scheme validation, allowing execution of arbitrary Android intents. This includes USSD codes, phone calls, SMS messages, and content provider access. The vulnerability is fixed in version 0.0.50. [truncated]