PT-2025-35521 · Mobsf · Mobsf

Noname1337H1

·

Published

2025-09-02

·

Updated

2025-09-03

·

CVE-2025-58161

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MobSF version 4.4.0
Description The GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the intended download directory from neighboring directories with similar path prefixes. This is a directory traversal issue leading to a data leak.
Recommendations Update to version 4.4.1 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-58161
GHSA-CCC3-FVFX-MW3V

Affected Products

Mobsf