PT-2025-19768 · Google+2 · Android Studio+2

Ssshah2131

·

Published

2025-05-05

·

Updated

2025-08-07

·

CVE-2025-46335

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mobile Security Framework (MobSF) versions up to and including 4.3.2
Description A Stored Cross-Site Scripting (XSS) issue has been identified in MobSF. The issue arises from improper sanitization of user-supplied SVG files during the Android APK analysis workflow. When an Android Studio project contains a malicious SVG file as an app icon and the project is zipped and uploaded to MobSF, the tool processes and extracts the contents without validating or sanitizing the SVG. The SVG file becomes publicly accessible via the web interface, and if it contains embedded JavaScript, accessing the URL via a browser leads to the execution of the script in the context of the MobSF user session, resulting in stored XSS.
Recommendations For versions up to and including 4.3.2, update to version 4.3.3 to fix the issue. As a temporary workaround, consider restricting access to the download endpoint, specifically to files with the .svg extension, to minimize the risk of exploitation. Avoid using the http://127.0.0.1:8081/download/filename.svg endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-09278
CVE-2025-46335
GHSA-MWFG-948F-2CC5

Affected Products

Android Studio
Mobsf
Red Os