PYSEC-2025-48

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/mobsf/PYSEC-2025-48.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2025-48
Aliases
Related
Published
2025-03-31T17:15:42Z
Modified
2025-06-12T23:12:02.499225Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.

References

Affected packages

PyPI / mobsf

Package

Affected ranges

Type
GIT
Repo
https://github.com/mobsf/mobile-security-framework-mobsf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.2

Affected versions

3.*

3.2.6
3.2.7
3.2.8
3.2.9
3.3.3
3.3.5
3.4.0
3.4.3
3.4.6
3.5.0
3.6.0
3.6.9
3.7.6
3.9.7

4.*

4.1.3
4.3.0