PT-2026-77243 · Mobsf · Mobsf
CVE-2026-68922
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MobSF versions prior to 4.5.1
Description
The
find icon path zip() function in mobsf/StaticAnalyzer/views/android/icon analysis.py fails to properly validate the android:icon value from the Android manifest. This allows an authenticated user to upload a specially crafted ZIP or APK file to perform path traversal, enabling the reading of server files that possess an ALLOWED EXTENSIONS suffix. The affected file is then copied to DWD DIR with the name -icon. and can be retrieved via the /download/ endpoint. Additionally, this behavior creates a file-existence oracle through the icon path report field, which allows an attacker to verify if a specific file exists on the server.Recommendations
Update to version 4.5.1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mobsf