CVE-2026-68927 LOW

CVE-2026-68927: MobSF: SSRF port restriction bypass in assetlinks_check

Vendor Mobsf
Product Mobile-Security-Framework-MobSF
Weakness CWE-918 · SSRF
Published August 18, 2026
Last update August 18, 2026

CVSS base score

3.0/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before appending a separately supplied android:port to the URL fetched by _check_url, allowing an authenticated user to upload a crafted APK that makes requests to an attacker-selected nonstandard port at /.well-known/assetlinks.json. With an attacker-controlled hostname and DNS rebinding between validation and the requests.get connection, the request can reach an internal service, although redirects remain disabled and the path is fixed. This issue is fixed in version 4.5.1.

Key dates

02Disclosure timeline

August 18, 2026 CVE published

Related vulnerabilities

04Related CVE