CVE-2023-42261: Opensecurity Mobile Security Framework
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.
Affected products
- Opensecurity Mobile Security Framework: up to and including 3.7.6; version 3.7.8 only
Published 2023-09-21. Last modified 2026-06-17.