Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3p2m-h2v6-g9mx | @mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobilenexthq
Mobilenexthq mobile Mcp |
|
| CPEs | cpe:2.3:a:mobilenexthq:mobile_mcp:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Mobilenexthq
Mobilenexthq mobile Mcp |
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobile-next
Mobile-next mobile-mcp |
|
| Vendors & Products |
Mobile-next
Mobile-next mobile-mcp |
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed directly to filesystem operations without validation, allowing an attacker to write files outside the intended workspace. Version 0.0.49 fixes the issue. | |
| Title | @mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T15:47:00.925Z
Reserved: 2026-03-24T22:20:06.211Z
Link: CVE-2026-33989
Updated: 2026-03-30T15:46:54.514Z
Status : Analyzed
Published: 2026-03-27T22:16:22.950
Modified: 2026-03-31T21:52:33.573
Link: CVE-2026-33989
No data.
OpenCVE Enrichment
Updated: 2026-04-02T07:55:18Z
Github GHSA