File Upload Vulnerability in MobSF Mobile Application Security Testing Tool
CVE-2026-68922

5.5MEDIUM

Key Information:

Vendor

Mobsf

Vendor
CVE Published:
18 August 2026

What is CVE-2026-68922?

The Mobile Security Framework (MobSF) contains a vulnerability in the icon path handling feature prior to version 4.5.1. This flaw allows an authenticated user to exploit the find_icon_path_zip function in the icon_analysis.py module. It permits the upload of specially crafted ZIP or APK files that, due to improper path construction, can read server files with a specified suffix, thus exposing those files through the /download/ endpoint. This vulnerability also provides an oracle for file existence checks via the icon_path report field, creating significant security implications for users leveraging this tool for mobile application security assessments.

Affected Version(s)

Mobile-Security-Framework-MobSF < 4.5.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.