<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:03:19 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-24805 — Local Privilege Escalation in MobSF</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-24805</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MobSF Mobile-Security-Framework-MobSF&lt;/p&gt;
&lt;p&gt;Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MobSF Mobile-Security-Framework-MobSF&lt;/p&gt;
&lt;p&gt;Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-24805</guid>
    </item>
    <item>
      <title>GHSA-79f6-p65j-3m2m — MobSF Local Privilege Escalation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-79f6-p65j-3m2m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;**Product:** Mobile Security Framework (MobSF)
**Version:** 4.3.0
**CWE-ID:** CWE-269: Improper Privilege Management
**CVSS vector v.4.0:** 7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N)
**CVSS vector v.3.1:** 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
**Description:** MobSF has a functionality of dividing users by roles. This functionality is not efficient, because any registered user can get API Token with all privileges.
**Impact:** Information Disclosure 
**Vulnerable component:** Code output component (`/source_code`)
**Exploitation conditions:** authorized user
**Mitigation:** Remove token output in the returned js-script
**Researcher:** Egor Filatov (Positive Technologies)&lt;/p&gt;
&lt;p&gt;## Research&lt;/p&gt;
&lt;p&gt;Researcher discovered zero-day vulnerability «Local Privilege Escalation» in Mobile Security Framework (MobSF).
To reproduce the vulnerability follow the steps below.&lt;/p&gt;
&lt;p&gt;•	 A user with minimal privileges is required, so the administrator must create a user account&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;215&amp;#34; alt=&amp;#34;fig1&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/43e02a50-bdd9-48d9-9194-73946fcc56d9&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;*Figure 1. Registration*&lt;/p&gt;
&lt;p&gt;•	Go to static analysis of any application&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1207&amp;#34; alt=&amp;#34;fig2&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/9ed141a7-a667-4a96-81fd-d81127874104&amp;#34; /&amp;gt;
 
*Figure 2. Static analysis*&lt;/p&gt;
&lt;p&gt;•	Go to the code review of the selected application and get a token with all privileges in the response&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1400&amp;#34; alt=&amp;#34;fig3&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;**Product:** Mobile Security Framework (MobSF)
**Version:** 4.3.0
**CWE-ID:** CWE-269: Improper Privilege Management
**CVSS vector v.4.0:** 7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N)
**CVSS vector v.3.1:** 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
**Description:** MobSF has a functionality of dividing users by roles. This functionality is not efficient, because any registered user can get API Token with all privileges.
**Impact:** Information Disclosure 
**Vulnerable component:** Code output component (`/source_code`)
**Exploitation conditions:** authorized user
**Mitigation:** Remove token output in the returned js-script
**Researcher:** Egor Filatov (Positive Technologies)&lt;/p&gt;
&lt;p&gt;## Research&lt;/p&gt;
&lt;p&gt;Researcher discovered zero-day vulnerability «Local Privilege Escalation» in Mobile Security Framework (MobSF).
To reproduce the vulnerability follow the steps below.&lt;/p&gt;
&lt;p&gt;•	 A user with minimal privileges is required, so the administrator must create a user account&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;215&amp;#34; alt=&amp;#34;fig1&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/43e02a50-bdd9-48d9-9194-73946fcc56d9&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;*Figure 1. Registration*&lt;/p&gt;
&lt;p&gt;•	Go to static analysis of any application&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1207&amp;#34; alt=&amp;#34;fig2&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/9ed141a7-a667-4a96-81fd-d81127874104&amp;#34; /&amp;gt;
 
*Figure 2. Static analysis*&lt;/p&gt;
&lt;p&gt;•	Go to the code review of the selected application and get a token with all privileges in the response&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1400&amp;#34; alt=&amp;#34;fig3&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-79f6-p65j-3m2m</guid>
    </item>
  </channel>
</rss>
