PatchSiren

mobile-next CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mobile-next CVE published 2026-04-06

CVE-2026-35394

CVE-2026-35394 is a high-severity vulnerability in the Mobile Next MCP server for mobile development and automation. The mobile_open_url tool passes user-supplied URLs directly to Android's intent system without scheme validation, allowing execution of arbitrary Android intents. This includes USSD codes, phone calls, SMS messages, and content provider access. The vulnerability is fixed in version 0.0.50. [truncated]