{"id":"CVE-2025-24805","aliases":["GHSA-79f6-p65j-3m2m","PYSEC-2026-1667"],"url":"https://o3.security/vulnerability/CVE-2025-24805","summary":"Local Privilege Escalation in MobSF","details":"**Product:** Mobile Security Framework (MobSF)\n**Version:** 4.3.0\n**CWE-ID:** CWE-269: Improper Privilege Management\n**CVSS vector v.4.0:** 7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N)\n**CVSS vector v.3.1:** 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)\n**Description:** MobSF has a functionality of dividing users by roles. This functionality is not efficient, because any registered user can get API Token with all privileges.\n**Impact:** Information Disclosure \n**Vulnerable component:** Code output component (`/source_code`)\n**Exploitation conditions:** authorized user\n**Mitigation:** Remove token output in the returned js-script\n**Researcher:** Egor Filatov (Positive Technologies)\n\n## Research \n\nResearcher discovered zero-day vulnerability «Local Privilege Escalation» in Mobile Security Framework (MobSF).\nTo reproduce the vulnerability follow the steps below.\n\n•\t A user with minimal privileges is required, so the administrator must create a user account\n\n<img width=\"215\" alt=\"fig1\" src=\"https://github.com/user-attachments/assets/43e02a50-bdd9-48d9-9194-73946fcc56d9\" />\n\n*Figure 1. Registration*\n\n•\tGo to static analysis of any application\n\n<img width=\"1207\" alt=\"fig2\" src=\"https://github.com/user-attachments/assets/9ed141a7-a667-4a96-81fd-d81127874104\" />\n \n*Figure 2. Static analysis*\n\n•\tGo to the code review of the selected application and get a token with all privileges in the response\n\n<img width=\"1400\" alt=\"fig3\" src=\"https://github.com/user-attachments/assets/bf8b704b-9067-4861-a7d3-05ec119d9a3f\" />\n \n*Figure 3. Token receiving*\n\n•\tThis token can be used to retrieve dynamic analysis information that has not been accessed before.\n\n![fig4](https://github.com/user-attachments/assets/fda8436b-de67-45b1-bb21-6cfbc9976f79)\n \n*Figure 4. No access demonstration*\n\n<img width=\"1412\" alt=\"fig5\" src=\"https://github.com/user-attachments/assets/dc8f639f-36b0-47d3-807d-58ae551fcbfc\" />\n \n*Figure 5. Token usage*\n\nAs a result, the user is able to escalate the privileges.\n\n\n_______________________\n\n### Please, assign all credits to: Egor Filatov (Positive Technologies)","published":"2025-02-05T18:41:02.991Z","modified":"2026-08-12T03:51:29.355879681Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mobsf","fixedVersion":"4.3.1"}],"fix":{"url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/05206e72cae35b311615a70e51e1a946955c5e83","label":"MobSF/Mobile-Security-Framework-MobSF@05206e7"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24805.json"},{"type":"ADVISORY","url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-79f6-p65j-3m2m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24805"},{"type":"FIX","url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/05206e72cae35b311615a70e51e1a946955c5e83"},{"type":"PACKAGE","url":"https://github.com/MobSF/Mobile-Security-Framework-MobSF"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.355879681Z"}}