PT-2026-77243 · Mobsf · Mobsf

CVE-2026-68922

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MobSF versions prior to 4.5.1
Description The find icon path zip() function in mobsf/StaticAnalyzer/views/android/icon analysis.py fails to properly validate the android:icon value from the Android manifest. This allows an authenticated user to upload a specially crafted ZIP or APK file to perform path traversal, enabling the reading of server files that possess an ALLOWED EXTENSIONS suffix. The affected file is then copied to DWD DIR with the name -icon. and can be retrieved via the /download/ endpoint. Additionally, this behavior creates a file-existence oracle through the icon path report field, which allows an attacker to verify if a specific file exists on the server.
Recommendations Update to version 4.5.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68922
GHSA-8J49-MMCX-4MP5
PYSEC-2026-3689

Affected Products

Mobsf