Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26369 | MobSF Path Traversal in GET /download/<filename> using absolute filenames |
Github GHSA |
GHSA-ccc3-fvfx-mw3v | MobSF Path Traversal in GET /download/<filename> using absolute filenames |
Wed, 03 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensecurity
Opensecurity mobile Security Framework |
|
| CPEs | cpe:2.3:a:opensecurity:mobile_security_framework:4.4.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensecurity
Opensecurity mobile Security Framework |
|
| Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobsf
Mobsf mobile Security Framework |
|
| Vendors & Products |
Mobsf
Mobsf mobile Security Framework |
Tue, 02 Sep 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the same prefix as DWD_DIR (e.g., .../downloads_bak, .../downloads.old). This is a Directory Traversal (escape) leading to a data leak. This issue has been patched in version 4.4.1. | |
| Title | MobSF Path Traversal in GET /download/<filename> using absolute filenames | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-02T19:25:49.966Z
Reserved: 2025-08-27T13:34:56.186Z
Link: CVE-2025-58161
Updated: 2025-09-02T19:25:05.880Z
Status : Analyzed
Published: 2025-09-02T01:15:30.170
Modified: 2025-09-03T15:48:43.537
Link: CVE-2025-58161
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:06Z
EUVD
Github GHSA