PatchSiren

MobSF CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW MobSF CVE published 2026-08-18

CVE-2026-68927

CVE-2026-68927 is a vulnerability in the MobSF mobile application security testing tool. An authenticated user can upload a crafted APK to make requests to an attacker-selected nonstandard port at /.well-known/assetlinks.json. This issue is fixed in version 4.5.1. The vulnerability allows potential unauthorized requests to internal services. Defenders should assess exposure and prioritize verification in [truncated]

MEDIUM MobSF CVE published 2026-08-18

CVE-2026-68924

CVE-2026-68924 debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T18:19:28.197Z and has not been modified since then. The NVD entry is currently Deferred. MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is [truncated]

MEDIUM MobSF CVE published 2026-08-18

CVE-2026-68923

A vulnerability in MobSF, a mobile application security testing tool, allows remote attackers to perform cross-site request forgery (CSRF) attacks on authenticated web endpoints. This issue, fixed in version 4.5.1, enables attackers to delete scans, upload or download applications, change passwords, or manage users with the victim's account permissions.

MEDIUM MobSF CVE published 2026-08-18

CVE-2026-68922

CVE-2026-68922 is a vulnerability in MobSF, a mobile application security testing tool. The vulnerability allows an authenticated user to upload a crafted ZIP or APK and read a server file with a specific suffix, then retrieve it through a predictable endpoint. This issue is caused by the find_icon_path_zip function in MobSF's icon_analysis.py, which uses the Android manifest android:icon value to constru [truncated]