PT-2024-2891 · Unknown · Mobile Security Framework

·

CVE-2024-31215

·

Published

2024-04-02

·

Updated

2026-07-07

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mobile Security Framework (MobSF) versions prior to 3.9.8
Description A Server-Side Request Forgery (SSRF) vulnerability exists in the firebase database check logic of the Mobile Security Framework (MobSF). This allows an attacker to cause the server to make a connection to internal-only services within the organization's infrastructure. When a malicious app is uploaded to the Static analyzer, it is possible to make internal requests.
Recommendations For versions prior to 3.9.8, update to version 3.9.8 or above to resolve the issue. As a temporary workaround, consider applying a code-level patch until a official patch is available.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03055
CVE-2024-31215
GHSA-WPFF-WM84-X5CX
PYSEC-2026-1676

Affected Products

Mobile Security Framework