<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:27:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09278</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09278</link>
      <description>bdu:2025-09278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09278</guid>
    </item>
    <item>
      <title>EUVD-2026-237671</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237671</link>
      <description>EUVD-2026-237671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237671</guid>
    </item>
    <item>
      <title>fkie_cve-2025-46335</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46335</link>
      <description>&lt;p&gt;Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow. Version 4.3.3 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow. Version 4.3.3 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-46335</guid>
    </item>
    <item>
      <title>GHSA-mwfg-948f-2cc5 — Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwfg-948f-2cc5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;**Vulnerable MobSF Versions:**  &amp;lt;= v4.3.2&lt;/p&gt;
&lt;p&gt;**CVSS V4.0 Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N)&lt;/p&gt;
&lt;p&gt;**Details:**
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions ≤ 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow.&lt;/p&gt;
&lt;p&gt;When an Android Studio project contains a malicious SVG file as an app icon (e.g path, /app/src/main/res/mipmap-hdpi/ic_launcher.svg), and the project is zipped and uploaded to MobSF, the tool processes and extracts the contents without validating or sanitizing the SVG.&lt;/p&gt;
&lt;p&gt;Upcon ZIP extraction this icon file is saved by MobSF to: user/.MobSF/downloads/&amp;lt;filename&amp;gt;.svg&lt;/p&gt;
&lt;p&gt;This file becomes publicly accessible via the web interface at:&lt;/p&gt;
&lt;p&gt;http://127.0.0.1:8081/download/filename.svg&lt;/p&gt;
&lt;p&gt;If the SVG contains embedded JavaScript (e.g., an XSS payload), accessing this URL via a browser leads to the execution of the script in the context of the MobSF user session, resulting in stored XSS.&lt;/p&gt;
&lt;p&gt;**Proof Of Concept:**&lt;/p&gt;
&lt;p&gt;1. Create a malicious SVG file (ic_launcher.svg) with an embedded XSS payload.&lt;/p&gt;
&lt;p&gt;![01](https://github.com/user-attachments/assets/9a89dec2-0671-490d-aba6-f38470bd84ee)&lt;/p&gt;
&lt;p&gt;2. Place the file in the Android Studio project directory: /app/src/main/res/mipmap-hdpi/ic_launcher.svg&lt;/p&gt;
&lt;p&gt;![02](https://github.com/user-attachments/assets/fc66f659-9f90-4be8-92c3-c5f26e1e11de)&lt;/p&gt;
&lt;p&gt;3. Zip the project directory and upload it to MobSF.&lt;/p&gt;
&lt;p&gt;![03](https:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;**Vulnerable MobSF Versions:**  &amp;lt;= v4.3.2&lt;/p&gt;
&lt;p&gt;**CVSS V4.0 Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N)&lt;/p&gt;
&lt;p&gt;**Details:**
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions ≤ 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow.&lt;/p&gt;
&lt;p&gt;When an Android Studio project contains a malicious SVG file as an app icon (e.g path, /app/src/main/res/mipmap-hdpi/ic_launcher.svg), and the project is zipped and uploaded to MobSF, the tool processes and extracts the contents without validating or sanitizing the SVG.&lt;/p&gt;
&lt;p&gt;Upcon ZIP extraction this icon file is saved by MobSF to: user/.MobSF/downloads/&amp;lt;filename&amp;gt;.svg&lt;/p&gt;
&lt;p&gt;This file becomes publicly accessible via the web interface at:&lt;/p&gt;
&lt;p&gt;http://127.0.0.1:8081/download/filename.svg&lt;/p&gt;
&lt;p&gt;If the SVG contains embedded JavaScript (e.g., an XSS payload), accessing this URL via a browser leads to the execution of the script in the context of the MobSF user session, resulting in stored XSS.&lt;/p&gt;
&lt;p&gt;**Proof Of Concept:**&lt;/p&gt;
&lt;p&gt;1. Create a malicious SVG file (ic_launcher.svg) with an embedded XSS payload.&lt;/p&gt;
&lt;p&gt;![01](https://github.com/user-attachments/assets/9a89dec2-0671-490d-aba6-f38470bd84ee)&lt;/p&gt;
&lt;p&gt;2. Place the file in the Android Studio project directory: /app/src/main/res/mipmap-hdpi/ic_launcher.svg&lt;/p&gt;
&lt;p&gt;![02](https://github.com/user-attachments/assets/fc66f659-9f90-4be8-92c3-c5f26e1e11de)&lt;/p&gt;
&lt;p&gt;3. Zip the project directory and upload it to MobSF.&lt;/p&gt;
&lt;p&gt;![03](https:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwfg-948f-2cc5</guid>
    </item>
    <item>
      <title>PYSEC-2026-1675 — Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1675</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;**Vulnerable MobSF Versions:**  &amp;lt;= v4.3.2&lt;/p&gt;
&lt;p&gt;**CVSS V4.0 Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N)&lt;/p&gt;
&lt;p&gt;**Details:**
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions ≤ 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow.&lt;/p&gt;
&lt;p&gt;When an Android Studio project contains a malicious SVG file as an app icon (e.g path, /app/src/main/res/mipmap-hdpi/ic_launcher.svg), and the project is zipped and uploaded to MobSF, the tool processes and extracts the contents without validating or sanitizing the SVG.&lt;/p&gt;
&lt;p&gt;Upcon ZIP extraction this icon file is saved by MobSF to: user/.MobSF/downloads/&amp;lt;filename&amp;gt;.svg&lt;/p&gt;
&lt;p&gt;This file becomes publicly accessible via the web interface at:&lt;/p&gt;
&lt;p&gt;http://127.0.0.1:8081/download/filename.svg&lt;/p&gt;
&lt;p&gt;If the SVG contains embedded JavaScript (e.g., an XSS payload), accessing this URL via a browser leads to the execution of the script in the context of the MobSF user session, resulting in stored XSS.&lt;/p&gt;
&lt;p&gt;**Proof Of Concept:**&lt;/p&gt;
&lt;p&gt;1. Create a malicious SVG file (ic_launcher.svg) with an embedded XSS payload.&lt;/p&gt;
&lt;p&gt;![01](https://github.com/user-attachments/assets/9a89dec2-0671-490d-aba6-f38470bd84ee)&lt;/p&gt;
&lt;p&gt;2. Place the file in the Android Studio project directory: /app/src/main/res/mipmap-hdpi/ic_launcher.svg&lt;/p&gt;
&lt;p&gt;![02](https://github.com/user-attachments/assets/fc66f659-9f90-4be8-92c3-c5f26e1e11de)&lt;/p&gt;
&lt;p&gt;3. Zip the project directory and upload it to MobSF.&lt;/p&gt;
&lt;p&gt;![03](https:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;**Vulnerable MobSF Versions:**  &amp;lt;= v4.3.2&lt;/p&gt;
&lt;p&gt;**CVSS V4.0 Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N)&lt;/p&gt;
&lt;p&gt;**Details:**
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions ≤ 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow.&lt;/p&gt;
&lt;p&gt;When an Android Studio project contains a malicious SVG file as an app icon (e.g path, /app/src/main/res/mipmap-hdpi/ic_launcher.svg), and the project is zipped and uploaded to MobSF, the tool processes and extracts the contents without validating or sanitizing the SVG.&lt;/p&gt;
&lt;p&gt;Upcon ZIP extraction this icon file is saved by MobSF to: user/.MobSF/downloads/&amp;lt;filename&amp;gt;.svg&lt;/p&gt;
&lt;p&gt;This file becomes publicly accessible via the web interface at:&lt;/p&gt;
&lt;p&gt;http://127.0.0.1:8081/download/filename.svg&lt;/p&gt;
&lt;p&gt;If the SVG contains embedded JavaScript (e.g., an XSS payload), accessing this URL via a browser leads to the execution of the script in the context of the MobSF user session, resulting in stored XSS.&lt;/p&gt;
&lt;p&gt;**Proof Of Concept:**&lt;/p&gt;
&lt;p&gt;1. Create a malicious SVG file (ic_launcher.svg) with an embedded XSS payload.&lt;/p&gt;
&lt;p&gt;![01](https://github.com/user-attachments/assets/9a89dec2-0671-490d-aba6-f38470bd84ee)&lt;/p&gt;
&lt;p&gt;2. Place the file in the Android Studio project directory: /app/src/main/res/mipmap-hdpi/ic_launcher.svg&lt;/p&gt;
&lt;p&gt;![02](https://github.com/user-attachments/assets/fc66f659-9f90-4be8-92c3-c5f26e1e11de)&lt;/p&gt;
&lt;p&gt;3. Zip the project directory and upload it to MobSF.&lt;/p&gt;
&lt;p&gt;![03](https:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1675</guid>
    </item>
  </channel>
</rss>
