Arbitrary File Write Vulnerability in MobSF Security Testing Tool
CVE-2025-58162

6.5MEDIUM

Key Information:

Vendor

Mobsf

Vendor
CVE Published:
2 September 2025

What is CVE-2025-58162?

In version 4.4.0 of the Mobile Security Framework (MobSF), an authenticated user can exploit a vulnerability by uploading a specially crafted file, allowing them to write arbitrary files to any directory that is writable by the MobSF process. This flaw poses significant risks to the integrity of the system by potentially allowing unauthorized access to sensitive files and data. The issue has been resolved in version 4.4.1, emphasizing the importance of keeping security tools up to date.

Affected Version(s)

Mobile-Security-Framework-MobSF = 4.4.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.