2061 Commits
Author SHA1 Message Date
7a4785fb3b chore: remove dead malwaredomainlist.com integration (#2687)
MALWARE_DB_URL pointed at malwaredomainlist.com, a service that has
been defunct for years, and nothing in the codebase ever fetched or
refreshed it - the only "data" behind malware_check() was a static
snapshot bundled in the repo whose newest entries date back to 2009.
That check ran on every scan against 16+ year old data without
anyone noticing, while maltrail_check() (which does self-update from
a live source) was the only domain check actually doing real work.

Removes malware_check(), its now-unused get_netloc() helper, the
stale bundled data file, and the unused MALWARE_DB_URL setting.
maltrail_check() is unaffected and remains the sole domain check.

Co-authored-by: alanhasn

Co-authored-by: Ajin Abraham <[email protected]>
2026-09-25 17:19:52 -07:00
dependabot[bot] 1262d3a5ec Bump docker/build-push-action from 7.3.0 to 7.4.0 (#2688)
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.3.0 to 7.4.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-22 19:17:14 -07:00
c78bf022fd fix: analyze native libraries from split APKs (#2685)
* fix: extract native libraries from split APKs

* docs: add APKS native library PoC

* fix: share one unzip budget across split APKs

Sibling splits are still extracted so native libraries are analyzed.
Those nested unzips now share one uncompressed-size cap, skip symlinks
and members that were never written, and do not fall back to OS unzip.

Co-authored-by: Ajin Abraham <[email protected]>

* chore: bump version to 4.5.4

Split APK native-library extraction now shares one unzip budget, so this release can move past 4.5.3.

Co-authored-by: Ajin Abraham <[email protected]>

* docs: remove APKS native library PoC image

Co-authored-by: Ajin Abraham <[email protected]>

* chore: suppress false positive CodeQL path-injection alerts

Mark the split APK file check and primary move as contained by is_safe_path so py/path-injection does not report them.

Co-authored-by: Ajin Abraham <[email protected]>

* test: remove split APK extraction tests

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor Agent <[email protected]>
Co-authored-by: Ajin Abraham <[email protected]>
2026-09-21 21:48:28 -04:00
Ajin AbrahamandCursor Agent d3869adc46 docs: note CSRF POST and DOM XSS rules in AGENTS.md (#2684)
Document that mutating dynamic-analysis actions must be POST with a CSRF
token, and that template auto-escaping does not protect innerHTML sinks.

Co-authored-by: Cursor Agent <[email protected]>
v4.5.3
2026-09-20 19:38:24 -07:00
Ajin Abraham c730571083 HOTFIX: Bump deps 2026-09-20 19:26:34 -07:00
Ajin Abraham 36ec4b82b8 bump signatures (#2682) 2026-09-20 18:11:06 -07:00
f57a3c997c feat: expose decompiled Android XML files via the view_source REST API (#2659)
* feat: expose decompiled Android XML files via the view_source REST API

AndroidManifest.xml and other resource XML files are already
decompiled to apktool_out/ during static analysis, but there was no
way to fetch them through the API - only Java/Kotlin/smali sources
were reachable via view_source, and the standalone manifest_view
page is web-only with no API route.

Add an 'xml' type to view_source that points at apktool_out/, and
register it in the API dispatcher's Android type set (it also
covers eclipse/studio/apk/java/smali there; xml needs to be added
explicitly or it falls through to the iOS handler). .xml was
already in the allowed file extension list, so no other validation
changes were needed. Path traversal protection (is_safe_path) is
unchanged and applies to the new type like every other one.

Co-authored-by: alanhasn

* fix: safely support XML across Android scan types

Co-authored-by: Ajin Abraham <[email protected]>

* fix: validate view source API parameters

Co-authored-by: Ajin Abraham <[email protected]>

* Remove ViewSourceXMLTest

Co-authored-by: Ajin Abraham <[email protected]>

* fix: address CodeQL findings on Android view_source

Use validated form cleaned_data for path construction, keep
exception details out of JSON error responses, and annotate
post-validation path checks as known CodeQL false positives.

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor Agent <[email protected]>
2026-09-20 18:04:55 -07:00
Ajin AbrahamandCursor Agent 2a8399fac9 Fix responsive layouts and request error handling (#2681)
* fix duplicate user and upload error handling

Co-authored-by: Ajin Abraham <[email protected]>

* fix: make analysis navigation and summaries responsive

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor Agent <[email protected]>
2026-09-20 17:47:36 -07:00
a8254bcbb8 fix: mitmdump process leaked and respawned on every dynamic analysis run (#2658)
* fix: mitmdump process leaked and respawned on every dynamic analysis run

mobsf_agents_setup() called create_ca() unconditionally on every
dynamic analysis session, spawning a new detached mitmdump process
even when the CA cert already existed. The spawned process was also
never stopped, so it stayed running indefinitely after the session
ended.

create_ca() now waits for the CA cert file to appear and terminates
mitmdump once it's done, and the redundant unconditional call in
mobsf_agents_setup() is removed in favor of the existing
get_ca_file() check (already used by install_mobsf_ca()).

Co-authored-by: alanhasn

* reap mitmdump after CA generation

Co-authored-by: Ajin Abraham <[email protected]>

* Update environment.py

* Fix comment formatting in mobsf_agents_setup

Removed period from comment about installing MITM RootCA.

---------

Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor Agent <[email protected]>
2026-09-20 16:54:36 -07:00
0d62285a2f Update for /maltrail-malware-domains.txt link (#2662)
* Update for /maltrail-malware-domains.txt link

Old and 404 link: https://raw.githubusercontent.com/stamparm/aux/master/maltrail-malware-domains.txt

Actual link: https://github.com/stamparm/trails/releases/latest/download/maltrail-malware-domains.txt

Thank you!

* fix Maltrail URL slash and raise DB download timeout

Correct the trails release download path and allow Maltrail updates enough time to fetch the large domain list.

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor Agent <[email protected]>
2026-09-20 16:45:29 -07:00
Ajin AbrahamandCursor 6592454800 Prepare 4.5.3 dependency release (#2680)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

* Fix iOS plist-derived path traversal

Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.

Co-authored-by: Cursor <[email protected]>

* correct version

* fix CSRF in dynamic analysis actions

Co-authored-by: Ajin Abraham <[email protected]>

* document HTTPTools host header SSRF advisory

Co-authored-by: Ajin Abraham <[email protected]>

* prepare 4.5.3 dependency release

Co-authored-by: Ajin Abraham <[email protected]>

* support LIEF 0.17 Mach-O symbol types

Co-authored-by: Ajin Abraham <[email protected]>

* pin GitHub Actions to immutable commits

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:37:19 -07:00
Ajin AbrahamandCursor a23ff75ec0 Fix CSRF in dynamic analysis actions (#2679)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

* Fix iOS plist-derived path traversal

Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.

Co-authored-by: Cursor <[email protected]>

* correct version

* fix CSRF in dynamic analysis actions

Co-authored-by: Ajin Abraham <[email protected]>

* document HTTPTools host header SSRF advisory

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:36:10 -07:00
Ajin AbrahamandCursor e2609ad5aa Fix iOS plist-derived path traversal (#2678)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

* Fix iOS plist-derived path traversal

Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.

Co-authored-by: Cursor <[email protected]>

* correct version

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:35:00 -07:00
Ajin AbrahamandCursor 70ecabcafb Reject inactive SAML users before ACS group updates (#2677)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:34:04 -07:00
Ajin AbrahamandCursor a04a42e768 Bound androguard ZIP member decompression (#2675)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:32:50 -07:00
Ajin AbrahamandCursor 388f26ad5e Harden path traversal against Windows root-relative escapes (#2673)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:30:53 -07:00
Ajin AbrahamandCursor 18bb89b672 Give gh an explicit repo so welcome comments work without a checkout. (#2674)
gh pr comment fails with "not a git repository" because this workflow
intentionally skips checkout; GH_REPO and -R keep pull_request_target
from needing a clone of untrusted PR code.

Co-authored-by: Cursor <[email protected]>
2026-09-20 14:12:09 -07:00
Ajin AbrahamandCursor f823a7cf6e Replace wow-actions/auto-comment with native gh comments. (#2672)
Use pull_request_target only for posting fixed welcome text, with no
checkout or PR code execution, so fork PRs can be commented on without
exposing a stolen write token.

Co-authored-by: Cursor <[email protected]>
2026-09-20 13:32:32 -07:00
Ajin AbrahamandCursor 42ee5dc7e9 Fix DNS rebinding SSRF with pinned safe HTTP requests. (#2670)
* Fix DNS rebinding SSRF with pinned safe HTTP requests.

Add shared SSRF-safe request helpers that resolve once, connect to validated public IPs while preserving Host/SNI, reject redirects and internal addresses, and fail closed when upstream proxies would bypass pinning. Migrate assetlinks, Firebase, APK downloader, malware geolocation, and httptools shutdown to the hardened paths.

Co-authored-by: Cursor <[email protected]>

* remove test file

* Address SSRF hardening review feedback

Co-authored-by: Cursor <[email protected]>

* Avoid reassigning stop_httptools url parameter.

Use a dedicated proxy_kill_url so SonarCloud no longer flags
parameter reassignment before the initial value is used.

Co-authored-by: Cursor <[email protected]>

* bump version + deps

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 13:23:01 -07:00
AdrienHutinelandAjin Abraham 533c3ecb2a fix!: apktool not extracting the pak informations properly (#2651)
Co-authored-by: Ajin Abraham <[email protected]>
2026-08-21 15:30:35 -07:00
Ayushman Chhabra da83a00de2 fix: typo normnal -> normal (#2652) 2026-08-21 15:27:42 -07:00
Ajin AbrahamandCursor 3f48c5deb5 ci: publish to PyPI with OIDC Trusted Publishing (#2646)
* ci: publish to PyPI with OIDC Trusted Publishing

Replace the long-lived PYPI_PASSWORD token with GitHub Actions OIDC
and pypa/gh-action-pypi-publish on release publish events.

Co-authored-by: Cursor <[email protected]>

* ci: drop inline comment on id-token permission

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
v4.5.2
2026-08-09 23:14:01 -07:00
Ajin AbrahamandCursor fe882bf0dc chore: bump Python dependencies (#2645)
* chore: bump Python dependencies

Refresh poetry.lock within existing constraints (Django 6.1, Frida,
libsast, and related transitive updates).

Co-authored-by: Cursor <[email protected]>

* chore: raise libsast constraint to ^3.1.8

Co-authored-by: Cursor <[email protected]>

* chore: refresh poetry.lock content-hash after libsast bump

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-08-09 22:47:36 -07:00
Ajin AbrahamandCursor 95321b5b2e Migrate VirusTotal integration to API v3. (#2644)
Replace deprecated v2 endpoints with v3 report/upload flows, add
large-file upload_url support up to 650MB, and normalize responses
for existing report templates. Refs #2560.

Co-authored-by: Cursor <[email protected]>
2026-08-09 18:31:11 -07:00
Ajin AbrahamandCursor a0f8a0ded1 ci/docker: supply-chain Actions updates and Postgres 18 compose layout (#2643)
* ci: bump Actions versions, pin Docker actions, add Dependabot

Keep CI supply chain current after the Docker SBOM work: update test,
publish, and CodeQL workflows, SHA-pin Docker setup/login actions, and
enable weekly GitHub Actions Dependabot updates.

Co-authored-by: Cursor <[email protected]>

* docker: use Postgres latest and PG18 data volume layout

Co-authored-by: Cursor <[email protected]>

* Bump version to 4.5.2

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-08-09 18:14:05 -07:00
e41d49bd0d Detect known secret formats in Android/iOS string analysis (#2640)
Add a shared high-confidence secret detector (secret_detection.py) for known credential formats.
Integrate it into Android/iOS string, resource, binary, and plist secret extraction.
Keep labeled known secrets at the top of Hardcoded Secrets reports.
Remove Amazon LWA rules from android_rules.yaml so SAST stays focused on code-level issues.


Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor <[email protected]>
2026-08-09 18:12:40 -07:00
a20d60bf12 ci: bump docker workflow actions and add SBOM attestations (#2639)
Bump Docker CI action majors across docker-latest.yml, docker-release.yml, and docker-test.yml:
actions/checkout v3 → v7
docker/setup-qemu-action / setup-buildx-action / login-action v3 → v4
docker/build-push-action v5 → pinned v7.3.0 (53b7df96c91f9c12dcc8a07bcb9ccacbed38856a)
Attach SBOM attestations (sbom: true) and pin provenance (provenance: mode=max) on image pushes (:latest and release tags).
Disable provenance on PR test builds (push: false), where registry attestations are not applicable.

---------

Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor <[email protected]>
2026-08-09 17:10:24 -07:00
EljeesandAjin Abraham 3eadf6cc0a fix(rules): match the literal mode argument in getSharedPreferences (#2638)
The world readable/writable patterns matched any argument list ending with 1 or 2, so decompiled identifiers such as var1, var2 or mode2 were reported as world permissions.

Signed-off-by: Eljees <[email protected]>
Co-authored-by: Ajin Abraham <[email protected]>
2026-08-09 16:57:21 -07:00
Zen1th53andAjin Abraham 4d85257b01 Fix formatting in SKIP_CLASS_PATH list (#2634)
this is very very important fix ;)

Co-authored-by: Ajin Abraham <[email protected]>
2026-08-09 16:54:07 -07:00
b76513a12f fix csrf error (#2633)
SAML identity providers (e.g., Keycloak) do not include the Origin header in their SAML requests. This causes Django's CSRF middleware to reject the request with a "null origin" error.
To resolve this, we disable CSRF validation for the SAML login endpoint, as the SAML protocol itself provides its own security mechanisms (signature and assertion validation), making the CSRF check redundant in this specific flow.
---------
Co-authored-by: Khabarov Konstantin Olegovich <[email protected]>
Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor <[email protected]>
2026-08-09 16:51:25 -07:00
8c7b9d80fc Update: certificate analysis (apksigner) (#2630)
Cert Analysis:
- updated apksigner.jar: was from build-tools 32.0.0, now from build-tools 37.0.0
- modified cert_analysis.py to be more apksigner-version-agnostic via get_signature_versions (backward compatible)
- cleaned up apksigtool_cert / get_cert_data for more generic shape handling

Apktool:
- updated apktool (now 3.0.3) and converter.py CLI args for apktool 3.x (order / deprecated flags)

Maintainer follow-ups:
- apktool bumped further to 3.0.3 (SHA256 verified against Bitbucket)
- apksigner checked against developer.android.com / build-tools — latest stable still 37.0.0; jar SHA256 matches Google zip
- Failsafe rework: always keep v1–v4 keys; merge apksigner results instead of replacing the dict; soft-fail (no re-raise) so apksigtool/androguard fallbacks still run
- Graceful degradation for malformed attacker-controlled certs/files:
  - safe wrappers around cert/pubkey parsing so one bad entry does not wipe all findings
  - apksigner subprocess timeout (BINARY_ANALYSIS_TIMEOUT)
  - tolerant minSdkVersion parsing
  - MANIFEST.MF read with errors='ignore'
  - cert_info failure return keeps a shaped dict (certificate_info / certificate_findings / certificate_summary)

Co-authored-by: Cursor <[email protected]>
---------
Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Cursor <[email protected]>
2026-08-09 16:41:07 -07:00
Ajin Abraham 62563ca429 [HOTFIX][Security] Security Updates July 5 2026 (#2627)
Security Fixes

[GHSA-8j49-mmcx-4mp5] Arbitrary File Read via Path Traversal in ZIP/APK Icon Extraction
The android:icon attribute from an APK manifest was interpolated into file paths without validation, allowing a crafted APK to read arbitrary files from the server. Fixed by adding is_path_traversal() and is_safe_path() guards in find_icon_path_zip. Dependency bump included.

[GHSA-3p54-567p-2wpr] CSRF Checks Not Enforced After Django Middleware Migration
The migration from the deprecated MIDDLEWARE_CLASSES to MIDDLEWARE omitted CsrfViewMiddleware, SecurityMiddleware, and XFrameOptionsMiddleware, leaving CSRF, HSTS, and clickjacking protections silently disabled. All three have been restored to the active MIDDLEWARE tuple. The now-dead MIDDLEWARE_CLASSES block has been removed to prevent future confusion.

[GHSA-x768-8642-mmq9] Zip Bomb Denial of Service via Per-File Size Limit Bypass
The per-file size check in ZIP extraction logged a warning on oversized members but was missing a continue, allowing files exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE to be extracted anyway as long as the aggregate limit was not reached. Fixed by adding the missing continue.

[GHSA-95px-34x5-p37h] SSRF Port Restriction Bypass in assetlinks_check
valid_host() was called with only the bare hostname, allowing android:port to be appended afterward without going through port validation, bypassing the HTTP/HTTPS-only restriction. Fixed with a two-layer approach: primary port allowlist check before URL assembly in get_browsable_activities, and a defence-in-depth re-check in _check_url.

Hardening

The hand-rolled safe_extract used os.path.abspath (symlink-blind) instead of os.path.realpath, creating a TOCTOU window where a symlink could redirect extraction outside the destination directory. Replaced with Python 3.12's tarfile.extractall(filter='data') (PEP 706), which rejects symlinks, hardlinks, absolute paths, and traversal members per-member before extraction. A robust realpath-based fallback is included for older Python versions.
Both download_app_data call sites in the iOS dynamic analyser now wrap app_container and tarfile with shlex.quote when building the SSH tar command, as defensive coding hygiene.
Refactoring

is_path_traversal, is_safe_path, clean_filename, cmd_injection_check, is_pipe_or_link, and is_attack_pattern were scattered across utils.py and shared.py. All have been moved to mobsf/MobSF/security.py as the single authoritative location for security primitives.
Developer Tooling

AGENTS.md / CLAUDE.md - AI agent guidelines
Added a coding-standards document for AI coding agents (Cursor, Claude, Codex) covering MobSF-specific secure-by-default patterns: path traversal guards, archive extraction safety, Django middleware active-tuple hygiene, split-validation anti-patterns (SSRF port bypass), guard completeness (continue/return/raise after every security check), and Django-specific security features (form validators, decorators, middleware). CLAUDE.md is a symlink to AGENTS.md.
v4.5.1
2026-07-05 16:55:49 -07:00
potato-20andAjin Abraham c098134845 Add Android WebView mixed-content detection rule (#2618)
Adds android_webview_mixed_content to the Android static-analysis ruleset.
It flags WebViews configured with MIXED_CONTENT_ALWAYS_ALLOW, which lets a
page loaded over HTTPS pull resources from insecure HTTP origins, exposing
the app to man-in-the-middle content injection (CWE-319 / OWASP-Mobile M3 /
MASVS-NETWORK-1).

The pattern matches only the insecure MIXED_CONTENT_ALWAYS_ALLOW mode and
not the safe MIXED_CONTENT_NEVER_ALLOW or MIXED_CONTENT_COMPATIBILITY_MODE
values. Verified with libsast: fires on the insecure mode and produces no
false positives on the safe modes.

Co-authored-by: Ajin Abraham <[email protected]>
2026-07-05 16:55:22 -07:00
Yushawn d045022d7d [HOTFIX] Fix false positive in debug symbol stripping check using objdump (#2616)
* Fix [BUG] Debug symbols stripped false positive #2502
2026-07-05 16:49:10 -07:00
6e875fb77b Jailbroken iOS Device Support (#2536)
Enables dynamic analysis on real jailbroken iOS devices connected via USB or WiFi SSH, complementing the existing Corellium-based iOS analysis.              
                                                                                                                                                                                                                                                                                                                                                                                                                                                                
  - SSH connectivity — connects to jailbroken devices over USB (via iproxy port forwarding) or WiFi using Paramiko SSH                                         
  - Frida instrumentation — spawns/attaches Frida on-device, with full hook support matching the existing Corellium flow                                       
  - Environment setup — installs AppSync Unified and Frida server on first run; supports both arm and arm64 devices                                            
  - Dynamic analysis — app file extraction, system log streaming (oslog), screenshot capture, process listing, and report generation
  - SSH terminal — execute shell commands on the device over SSH

---------

Co-authored-by: CylentSec <[email protected]>
Co-authored-by: Oz <[email protected]>
2026-03-23 01:46:03 -07:00
Ajin Abraham 6f8a43c1b7 [SECURITY][HOTFIX] Security Fixes and Hardening (#2600)
* Fix GHSA-hqjr-43r5-9q58

* Update security docs

* Security hardening

* Bump deps
v4.4.6
2026-03-21 14:50:01 -07:00
df069296d4 Disable setting RequestedAuthnContext during saml request (#2580)
Co-authored-by: Thomas Kreuzer <[email protected]>
Co-authored-by: Ajin Abraham <[email protected]>
2026-03-21 12:17:47 -07:00
Ajin Abraham 2b08dd050e [SECURITY] Security Update + Dependency Bump (#2584)
* Bump Dependencies
* Fix a Stored XSS: GHSA-8hf7-h89p-3pqj
* Remove all  | safe in templates and HTML from Python
* Add permissions to Github Actions
v4.4.5
2026-01-25 22:33:34 -08:00
457d1e61f3 Improve error handling and logging in MalwareDomainCheck (#2555)
* Improve error handling and logging in MalwareDomainCheck


---------

Co-authored-by: Saurabh <[email protected]>
Co-authored-by: Ajin Abraham <[email protected]>
2025-12-14 21:32:03 -08:00
Ajin Abraham 4b004f3817 HOTFIX: Fix AppSec Score Card for iOS 2025-12-08 19:17:25 -08:00
Ajin Abraham 2c712e2ebc [HOTFIX] Dec 2025 QA + Bug Fixes (#2574)
* Dependency bump
* Fix [FEATURE] urls should be extracted as case-sensitive #2491
* Fix Code analysis -> IP Address disclosure flags on invalid IP's (Version Numbers) #2562
2025-12-07 21:34:08 -08:00
Sai Prathik RandSai Prathik R e3e539cd59 feat: Update URL extraction to preserve case sensitivity (#2550)
Bug 2491, which stated that the URLs were being converted to lowercase, which potentially caused issues for URLs with uppercase characters.

Co-authored-by: Sai Prathik R <[email protected]>
2025-12-07 20:37:58 -08:00
Ajin Abraham 9b6e0f0fe4 Socket Supply Chain Scan (#2559)
Socket Supply Chain Firewall
2025-10-04 15:04:04 -07:00
dependabot[bot] 3539414fe9 Bump django from 5.2.6 to 5.2.7 (#2558)
Bumps [django](https://github.com/django/django) from 5.2.6 to 5.2.7.
- [Commits](https://github.com/django/django/compare/5.2.6...5.2.7)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-01 21:59:14 -07:00
Ajin Abraham e371db8388 [HOTFIX] Update Slack Join Link (#2556)
* Update README.md

* Update SUPPORT.md

* Update bug_report.md

* Update CONTRIBUTING.md

* Update auto-comment.yml
2025-09-30 10:54:10 -07:00
Ajin Abraham 5d1096d458 Hotfix: Fix LIEF nx and arc check 2025-09-07 12:33:53 -07:00
Ajin Abraham de7bf03656 Python 3.13 Support (#2546)
* Python Support updated to 3.12-3.13
* Bump mitmproxy
* Bump httptools
* Remove pinned xmlsec, lxml
* Android Permission Update
* Updates Signatures
v4.4.2
2025-08-30 23:46:20 -07:00
Ajin Abraham 7f3bc086c0 [Security] Fix Vulnerabilities Aug 2025 MobSF v4.4.1 (#2545)
Bump dependencies
Fix Security Vulnerabilities reported by @noname1337h1
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-9gh8-9r95-3fc3
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-ccc3-fvfx-mw3v
v4.4.1
2025-08-30 19:28:41 -07:00
49537563cc fix(ios_analyzer): Correctly resolve executable path in .app bundles (#2533)
* fix(ios_analyzer): Correctly resolve executable path in .app bundles

The previous method for locating the executable within an IPA file was failing for apps with spaces in their `.app` bundle name. The logic incorrectly performed a string replacement on the full path of the bundle, resulting in an invalid path to the binary.

This commit refactors the path resolution logic to use `pathlib` features correctly. It now finds the `.app` directory as a `Path` object and uses the `.stem` attribute to reliably determine the executable's name. This approach is more robust, properly handles spaces and special characters in filenames, and avoids fragile string manipulation.

* Add doc string back

* Update mobsf/StaticAnalyzer/views/ios/binary_analysis.py

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Ajin Abraham <[email protected]>
Co-authored-by: Copilot <[email protected]>
2025-07-11 23:36:21 -07:00
Ajin Abraham 7e0355c51d June 22nd 2025 updates (#2530)
* Breaking change: Frida 17+ support and script updates
* Breaking change: Corellium iOS device must install frida >=17
* Updated Frida scripts for logging, ssl/cert pinning bypass
* Added bridges support to frida
* Poetry dependency updates
* Fix Frida Code Editor code alignment issues
* Fix Google Play Scrapper timeout issues behind proxy
* Apply MobSF proxy settings to standalone tools_download.py
2025-06-23 00:57:33 -07:00