PT-2025-5747 · Unknown · Mobile Security Framework

Egor Filatov

·

Published

2025-02-05

·

Updated

2025-02-06

·

CVE-2025-24805

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: Mobile Security Framework (MobSF) versions prior to 4.3.1
Description: The issue allows a local user with minimal privileges to use an access token for materials for scopes which it should not be accepted. This is due to improper privilege management, where any registered user can get an API token with all privileges. The vulnerable component is the code output component, and exploitation requires an authorized user. There are no known workarounds for this issue.
Recommendations: For versions prior to 4.3.1, upgrade to version 4.3.1 to address the issue. As a temporary workaround, consider removing token output in the returned js-script to minimize the risk of exploitation. Restrict access to the code output component (/source code) to minimize the risk of exploitation. Avoid using the API token with all privileges in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08882
CVE-2025-24805
GHSA-79F6-P65J-3M2M

Affected Products

Mobile Security Framework