VDB
KO
HIGH 7.5

GHSA-f42p-vc8p-7x54

MobSF allows attackers to read arbitrary files via a crafted HTTP request

Details

Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the `StaticAnalyzer/views.py` script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / mobsf
Introduced in: 0 Fixed in: 0.9.3
Fix pip install --upgrade 'mobsf>=0.9.3'

References