CVE-2025-24805
published 2025-02-05CVE-2025-24805: Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.1th percentile
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mobsf | mobile-security-framework-mobsf | — | — |
| opensecurity | mobile_security_framework | < 4.3.1 | 4.3.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MobSF Local Privilege Escalation
ghsa·2025-02-05
CVE-2025-24805 [HIGH] CWE-269 MobSF Local Privilege Escalation
MobSF Local Privilege Escalation
**Product:** Mobile Security Framework (MobSF)
**Version:** 4.3.0
**CWE-ID:** CWE-269: Improper Privilege Management
**CVSS vector v.4.0:** 7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N)
**CVSS vector v.3.1:** 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
**Description:** MobSF has a functionality of dividing users by roles. This functionality is not efficient, because any registered user can get API Token with all privileges.
**Impact:** Information Disclosure
**Vulnerable component:** Code output component (`/source_code`)
**Exploitation conditions:** authorized user
**Mitigation:** Remove token output in the returned js-script
**Researcher:** Egor Filatov (Positive Technologies)
## Research
Researcher discovered zero-day vulnerability «Local
OSV
MobSF Local Privilege Escalation
osv·2025-02-05
CVE-2025-24805 [HIGH] MobSF Local Privilege Escalation
MobSF Local Privilege Escalation
**Product:** Mobile Security Framework (MobSF)
**Version:** 4.3.0
**CWE-ID:** CWE-269: Improper Privilege Management
**CVSS vector v.4.0:** 7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N)
**CVSS vector v.3.1:** 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
**Description:** MobSF has a functionality of dividing users by roles. This functionality is not efficient, because any registered user can get API Token with all privileges.
**Impact:** Information Disclosure
**Vulnerable component:** Code output component (`/source_code`)
**Exploitation conditions:** authorized user
**Mitigation:** Remove token output in the returned js-script
**Researcher:** Egor Filatov (Positive Technologies)
## Research
Researcher discovered zero-day vulnerability «Local
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-05
Published