Security Vulnerability in MobSF Mobile Application Testing Tool
CVE-2026-68927
3LOW
What is CVE-2026-68927?
A significant vulnerability exists in the MobSF mobile application security testing tool that allows authenticated users to upload malicious APK files. These crafted APKs can exploit a weakness in the way the application validates the Android manifest, specifically its handling of the android:host attribute combined with a separately supplied android:port in the URL. This flaw can potentially enable attackers to direct requests to a nonstandard port on an attacker-controlled hostname, facilitating illicit access to internal services. The issue has been addressed in MobSF version 4.5.1, which mitigates the risk associated with these types of requests.
Affected Version(s)
Mobile-Security-Framework-MobSF < 4.5.1
