PT-2025-13807 · Unknown · Mobile Security Framework

·

CVE-2025-31116

·

Published

2025-03-31

·

Updated

2025-06-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mobile Security Framework (MobSF) versions prior to 4.3.2
Description The issue concerns a vulnerability in the valid host() function that uses socket.gethostbyname(), making it susceptible to SSRF abuse via the DNS rebinding technique. This vulnerability is related to the Mobile Security Framework (MobSF), a tool for pen-testing, malware analysis, and security assessment that performs static and dynamic analysis.
Recommendations For versions prior to 4.3.2, update to version 4.3.2 to resolve the issue. As a temporary workaround, consider restricting the use of the valid host() function until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-31116
GHSA-FCFQ-M8P6-GW56
PYSEC-2025-48

Affected Products

Mobile Security Framework