Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile.
A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1325 Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
Github GHSA Github GHSA GHSA-wpff-wm84-x5cx Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 30 Jun 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Opensecurity
Opensecurity mobile Security Framework
CPEs cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*
Vendors & Products Opensecurity
Opensecurity mobile Security Framework

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:46:04.599Z

Reserved: 2024-03-29T14:16:31.901Z

Link: CVE-2024-31215

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:22.680Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T16:15:09.787

Modified: 2025-06-30T13:04:19.583

Link: CVE-2024-31215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.