CVE-2026-24490: Opensecurity Mobile Security Framework
Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.
MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host` attribute from `<data android:scheme="android_secret_code">` elements is rendered in HTML reports without sanitization, enabling session hijacking and account takeover. Version 4.4.5 fixes the issue.
Affected products
- Opensecurity Mobile Security Framework: before 4.4.5 (fixed in 4.4.5)
Published 2026-01-27. Last modified 2026-06-17.