PT-2026-30323 · Unknown · Mobile Next

Manthanghasadiya

·

Published

2026-04-04

·

Updated

2026-04-06

·

CVE-2026-35394

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mobile Next versions prior to 0.0.50
Description The mobile open url tool in Mobile Next passes user-supplied URLs directly to Android's intent system without scheme validation, potentially allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. This could allow an attacker, via prompt injection, to execute dangerous intents on a connected mobile device. The vulnerability is exploitable through malicious documents or websites that inject instructions into an AI agent controlling the MCP server. An attacker could execute USSD codes, initiate phone calls to premium rate numbers, draft SMS messages with attacker-controlled content, and access content providers like contacts, SMS, and call logs.
Recommendations Upgrade to version 0.0.50 or later. Users requiring other URL schemes can set MOBILEMCP ALLOW UNSAFE URLS=1.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-35394
GHSA-5QHV-X9J4-C3VM

Affected Products

Mobile Next