File Upload Vulnerability in MobSF Mobile Application Security Testing Tool
CVE-2026-68922
5.5MEDIUM
What is CVE-2026-68922?
The Mobile Security Framework (MobSF) contains a vulnerability in the icon path handling feature prior to version 4.5.1. This flaw allows an authenticated user to exploit the find_icon_path_zip function in the icon_analysis.py module. It permits the upload of specially crafted ZIP or APK files that, due to improper path construction, can read server files with a specified suffix, thus exposing those files through the /download/ endpoint. This vulnerability also provides an oracle for file existence checks via the icon_path report field, creating significant security implications for users leveraging this tool for mobile application security assessments.
Affected Version(s)
Mobile-Security-Framework-MobSF < 4.5.1
