CVE-2023-42261: Opensecurity Mobile Security Framework

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.

Affected products

  • Opensecurity Mobile Security Framework: up to and including 3.7.6; version 3.7.8 only

Published 2023-09-21. Last modified 2026-06-17.