Document that mutating dynamic-analysis actions must be POST with a CSRF
token, and that template auto-escaping does not protect innerHTML sinks.
Co-authored-by: Cursor Agent <[email protected]>
* Harden path traversal checks for Windows root-relative escapes.
Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.
Co-authored-by: Cursor <[email protected]>
* Restrict network security config names to a basename.
CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.
Co-authored-by: Cursor <[email protected]>
* Use os.path.basename for CodeQL-recognized path sanitization.
Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.
Co-authored-by: Cursor <[email protected]>
* Drop CodeQL-appeasement basename sanitization from network config reads.
is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.
Co-authored-by: Cursor <[email protected]>
* Bound androguard ZIP member decompression
Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.
Co-authored-by: Cursor <[email protected]>
* Reject inactive SAML users before ACS group updates.
Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.
Co-authored-by: Cursor <[email protected]>
* Return the ACS error page for inactive users instead of raising Exception.
Co-authored-by: Cursor <[email protected]>
* Fix iOS plist-derived path traversal
Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.
Co-authored-by: Cursor <[email protected]>
* correct version
* fix CSRF in dynamic analysis actions
Co-authored-by: Ajin Abraham <[email protected]>
* document HTTPTools host header SSRF advisory
Co-authored-by: Ajin Abraham <[email protected]>
* prepare 4.5.3 dependency release
Co-authored-by: Ajin Abraham <[email protected]>
* support LIEF 0.17 Mach-O symbol types
Co-authored-by: Ajin Abraham <[email protected]>
* pin GitHub Actions to immutable commits
Co-authored-by: Ajin Abraham <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>
* Harden path traversal checks for Windows root-relative escapes.
Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.
Co-authored-by: Cursor <[email protected]>
* Restrict network security config names to a basename.
CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.
Co-authored-by: Cursor <[email protected]>
* Use os.path.basename for CodeQL-recognized path sanitization.
Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.
Co-authored-by: Cursor <[email protected]>
* Drop CodeQL-appeasement basename sanitization from network config reads.
is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.
Co-authored-by: Cursor <[email protected]>
* Bound androguard ZIP member decompression
Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.
Co-authored-by: Cursor <[email protected]>
* Reject inactive SAML users before ACS group updates.
Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.
Co-authored-by: Cursor <[email protected]>
* Return the ACS error page for inactive users instead of raising Exception.
Co-authored-by: Cursor <[email protected]>
* Fix iOS plist-derived path traversal
Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.
Co-authored-by: Cursor <[email protected]>
* correct version
* fix CSRF in dynamic analysis actions
Co-authored-by: Ajin Abraham <[email protected]>
* document HTTPTools host header SSRF advisory
Co-authored-by: Ajin Abraham <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>
* Harden path traversal checks for Windows root-relative escapes.
Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.
Co-authored-by: Cursor <[email protected]>
* Restrict network security config names to a basename.
CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.
Co-authored-by: Cursor <[email protected]>
* Use os.path.basename for CodeQL-recognized path sanitization.
Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.
Co-authored-by: Cursor <[email protected]>
* Drop CodeQL-appeasement basename sanitization from network config reads.
is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.
Co-authored-by: Cursor <[email protected]>
* Bound androguard ZIP member decompression
Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.
Co-authored-by: Cursor <[email protected]>
* Reject inactive SAML users before ACS group updates.
Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.
Co-authored-by: Cursor <[email protected]>
* Return the ACS error page for inactive users instead of raising Exception.
Co-authored-by: Cursor <[email protected]>
* Fix iOS plist-derived path traversal
Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.
Co-authored-by: Cursor <[email protected]>
* correct version
---------
Co-authored-by: Cursor <[email protected]>
* Harden path traversal checks for Windows root-relative escapes.
Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.
Co-authored-by: Cursor <[email protected]>
* Restrict network security config names to a basename.
CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.
Co-authored-by: Cursor <[email protected]>
* Use os.path.basename for CodeQL-recognized path sanitization.
Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.
Co-authored-by: Cursor <[email protected]>
* Drop CodeQL-appeasement basename sanitization from network config reads.
is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.
Co-authored-by: Cursor <[email protected]>
* Bound androguard ZIP member decompression
Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.
Co-authored-by: Cursor <[email protected]>
* Reject inactive SAML users before ACS group updates.
Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.
Co-authored-by: Cursor <[email protected]>
* Return the ACS error page for inactive users instead of raising Exception.
Co-authored-by: Cursor <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>
* Harden path traversal checks for Windows root-relative escapes.
Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.
Co-authored-by: Cursor <[email protected]>
* Restrict network security config names to a basename.
CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.
Co-authored-by: Cursor <[email protected]>
* Use os.path.basename for CodeQL-recognized path sanitization.
Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.
Co-authored-by: Cursor <[email protected]>
* Drop CodeQL-appeasement basename sanitization from network config reads.
is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.
Co-authored-by: Cursor <[email protected]>
* Bound androguard ZIP member decompression
Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.
Co-authored-by: Cursor <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>
* Harden path traversal checks for Windows root-relative escapes.
Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.
Co-authored-by: Cursor <[email protected]>
* Restrict network security config names to a basename.
CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.
Co-authored-by: Cursor <[email protected]>
* Use os.path.basename for CodeQL-recognized path sanitization.
Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.
Co-authored-by: Cursor <[email protected]>
* Drop CodeQL-appeasement basename sanitization from network config reads.
is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.
Co-authored-by: Cursor <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>
gh pr comment fails with "not a git repository" because this workflow
intentionally skips checkout; GH_REPO and -R keep pull_request_target
from needing a clone of untrusted PR code.
Co-authored-by: Cursor <[email protected]>
Use pull_request_target only for posting fixed welcome text, with no
checkout or PR code execution, so fork PRs can be commented on without
exposing a stolen write token.
Co-authored-by: Cursor <[email protected]>
* Fix DNS rebinding SSRF with pinned safe HTTP requests.
Add shared SSRF-safe request helpers that resolve once, connect to validated public IPs while preserving Host/SNI, reject redirects and internal addresses, and fail closed when upstream proxies would bypass pinning. Migrate assetlinks, Firebase, APK downloader, malware geolocation, and httptools shutdown to the hardened paths.
Co-authored-by: Cursor <[email protected]>
* remove test file
* Address SSRF hardening review feedback
Co-authored-by: Cursor <[email protected]>
* Avoid reassigning stop_httptools url parameter.
Use a dedicated proxy_kill_url so SonarCloud no longer flags
parameter reassignment before the initial value is used.
Co-authored-by: Cursor <[email protected]>
* bump version + deps
---------
Co-authored-by: Cursor <[email protected]>
Replace deprecated v2 endpoints with v3 report/upload flows, add
large-file upload_url support up to 650MB, and normalize responses
for existing report templates. Refs #2560.
Co-authored-by: Cursor <[email protected]>
Security Fixes
[GHSA-8j49-mmcx-4mp5] Arbitrary File Read via Path Traversal in ZIP/APK Icon Extraction
The android:icon attribute from an APK manifest was interpolated into file paths without validation, allowing a crafted APK to read arbitrary files from the server. Fixed by adding is_path_traversal() and is_safe_path() guards in find_icon_path_zip. Dependency bump included.
[GHSA-3p54-567p-2wpr] CSRF Checks Not Enforced After Django Middleware Migration
The migration from the deprecated MIDDLEWARE_CLASSES to MIDDLEWARE omitted CsrfViewMiddleware, SecurityMiddleware, and XFrameOptionsMiddleware, leaving CSRF, HSTS, and clickjacking protections silently disabled. All three have been restored to the active MIDDLEWARE tuple. The now-dead MIDDLEWARE_CLASSES block has been removed to prevent future confusion.
[GHSA-x768-8642-mmq9] Zip Bomb Denial of Service via Per-File Size Limit Bypass
The per-file size check in ZIP extraction logged a warning on oversized members but was missing a continue, allowing files exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE to be extracted anyway as long as the aggregate limit was not reached. Fixed by adding the missing continue.
[GHSA-95px-34x5-p37h] SSRF Port Restriction Bypass in assetlinks_check
valid_host() was called with only the bare hostname, allowing android:port to be appended afterward without going through port validation, bypassing the HTTP/HTTPS-only restriction. Fixed with a two-layer approach: primary port allowlist check before URL assembly in get_browsable_activities, and a defence-in-depth re-check in _check_url.
Hardening
The hand-rolled safe_extract used os.path.abspath (symlink-blind) instead of os.path.realpath, creating a TOCTOU window where a symlink could redirect extraction outside the destination directory. Replaced with Python 3.12's tarfile.extractall(filter='data') (PEP 706), which rejects symlinks, hardlinks, absolute paths, and traversal members per-member before extraction. A robust realpath-based fallback is included for older Python versions.
Both download_app_data call sites in the iOS dynamic analyser now wrap app_container and tarfile with shlex.quote when building the SSH tar command, as defensive coding hygiene.
Refactoring
is_path_traversal, is_safe_path, clean_filename, cmd_injection_check, is_pipe_or_link, and is_attack_pattern were scattered across utils.py and shared.py. All have been moved to mobsf/MobSF/security.py as the single authoritative location for security primitives.
Developer Tooling
AGENTS.md / CLAUDE.md - AI agent guidelines
Added a coding-standards document for AI coding agents (Cursor, Claude, Codex) covering MobSF-specific secure-by-default patterns: path traversal guards, archive extraction safety, Django middleware active-tuple hygiene, split-validation anti-patterns (SSRF port bypass), guard completeness (continue/return/raise after every security check), and Django-specific security features (form validators, decorators, middleware). CLAUDE.md is a symlink to AGENTS.md.
Enables dynamic analysis on real jailbroken iOS devices connected via USB or WiFi SSH, complementing the existing Corellium-based iOS analysis.
- SSH connectivity — connects to jailbroken devices over USB (via iproxy port forwarding) or WiFi using Paramiko SSH
- Frida instrumentation — spawns/attaches Frida on-device, with full hook support matching the existing Corellium flow
- Environment setup — installs AppSync Unified and Frida server on first run; supports both arm and arm64 devices
- Dynamic analysis — app file extraction, system log streaming (oslog), screenshot capture, process listing, and report generation
- SSH terminal — execute shell commands on the device over SSH
---------
Co-authored-by: CylentSec <[email protected]>
Co-authored-by: Oz <[email protected]>
* Fix false positives caused in Android manifest analysis
* Dep bumps + Support HTTPS upgrade for Assetlinks check
* MobSF version bump to 4.3.0
---------
Co-authored-by: Nick Lupien <[email protected]>
* Dockerfile QA
* Add sdk-build-tools to Docker image
* Replace biplist with plistlib std lib
* Fixed a bug in iOS pbxproj parsing
* Added support for APK parsing with aapt2/aapt
* Use aapt/aapt2 as a fallback for APK parsing, files listing and string extraction
* Added "started at" to Scan task queue model #2463
* Tasks List API to return string status #2464
* Replaced all minidom calls with defusedxml.minidom
* Code QA on android manifest data extraction and parsing
* Improved android file analysis
* Improved android manifest data extraction
* Improved android icon file extraction
* Improved android app name extraction
* Improved android appstore package details extraction
* Android string extraction to fallback on aapt2 strings
* APK analysis arguments refactor
* Handle packed APKs, refactor unzip to handle malformed APK files
* Handle reserved filename conflict during ZIP extraction
* Explicit Zipslip handling during ZIP extraction
* Graceful files extraction on unzip failure
* Removed bail out and continue analysis
* Moved androguard parsing to the start of static analysis
* AndroidManifest.xml fallback from apktool to androguard during extraction and parsing
* Updated Tasks UI to show started at
* Androguard 293ab2d89ab9ce011c7dbbc5df3c876172875a1c update
* AXML Parser warn "reserved must be zero!" instead of raise
* Fallback on get app name when androguard returns empty string
* Updated permissions
* Added and updated permission mapping rules
* Handle errors gracefully from get_app_name and icon_analysis
* Add new scans in tasks view without needing and explicit refresh
* Optimizing downloads, adding downloads for source code types and windows appx
- Added malware lookup using SHA2 with VirusTotal, Triage, Hybrid Analysis, and MetaDefender.
- Fixed permissions of extracted files to counter anti-analysis techniques.
- Resolved APK parsing errors in `androguard`.
- Handled exceptions in `string_on_binary`.
- Optimized APK ZIP analysis for improved performance.
- Fixed untar permission errors in dynamic analysis.
- Added bypass for SSL pinning in Boye's `AbstractVerifier`.
- Updated bypass for SSL pinning in Appmattus's `CertificateTransparencyInterceptor`.
- Introduced SSL pinning detector script.
- Improved Frida intent dumper script.
- Added Frida intent tracer script.
- Introduced timeouts for all HTTP calls.
- Added `django-q2`-based asynchronous scans for Android and iOS binaries and source code.
- Fixed bug in certificate analysis.
- Enabled asynchronous scans in Docker Compose setup.
- Performed QA for Android and iOS SAST modules.
- Added Frida script for `audit-webview`.
- Introduced Frida script for `trace-javascript-interface`.
- Upgraded `libsast` for improved file reading, multiprocessing, and multithreading.
- Fixed PNG crush issues on Darwin systems.
- Performed QA on the home screen UI.
- Updated `httptools` and `libsast` dependencies.
* Anti-analysis bypass
- JADX fallback to DEX files on APK decompilation failure
- apktool fallback to androguard for AndroidManifest.xml extraction
- apksigner.jar fallback to apksigtool/androguard for signature version extraction
- Graceful erorrs for failures instead of exceptions
* APKID QA.
* Bash and Batch file script QA.
* Android Report template optimizations on how exported components are displayed.
* Clickable Android Activities, Services, Providers and Recievers.
* Updated Android version support to 11.0 for Android Studio AVD.
* Created helper scripts for AVDs `scripts/start_avd.sh` and `scripts/start_avd.ps1`.
* Support custom home from environment variables
* Reduce iOS binary findings severity to warning from high
* Code QA and dependency updates
* docker-compose QA, added example nginx config
* Added docker-compose_swarm.yml by @antonkap add support for docker secrets
* IPA PNG Uncrush support for Windows and Linux #2397
Support time out for SAST and Binary scans
Search by MD5, package name, file name and app name.
Search REST API + docs + tests
Firebase remote config check [FEATURE] Add support for Firebase Remote Config information #2429
autopep8
* Dockerfile: migrate from Ubuntu to Debian Bookworm
* Update and MachO and ELF Analysis
* Update docker compose with postgres
* JDK bump to 22.0.2
* Python bump to 3.12
* Bump jadx, apktool, vd2svg, bundletool
* Remove jadx from repo and download it dynamically during setup
* Install jadx during docker build
* Replace deprecated dependencies
* Bump httptools
* Postgres Support by default
* Bump LIEF to latest, reintroduce PIE checks for ELF
* Fixes#2430#2432#2395
* Bug Fixes
Authentication and Authorization (`Maintainer` , Viewer`) support in MobSF
* Basic User Management
* Bug Fixes in Runtime Executable Tampering
* Ratelimiting support for login endpoint
* Disable AuthZ/AuthN for REST API and also via ENV VAR `MOBSF_DISABLE_AUTHENTICATION=1`
* Bug Fix#2285
* Bug Fix Icon Analysis Nonetype
* Update SSRF Filter
* Dependency Bump
* Beta to Stable release from V4
* Runs with DEBUG=False
* New home screen UI
This PR strips out androguard and it's dependencies from MobSF.
Extract androguard related functions used by MobSF.
Some dependencies such as pyQt5 from apkinspector is breaking the ARM64 docker image.
This should address that issue.
In future, we will have to copy over any fixes to axml, apk, public, types from androguard and ZipEntry from apkinspector.
We won't be adding linting to these files. The extracted functions will be considered as an external tool.
* [SECURITY] Fixes an LFI reported by @0x33c0unt - A crafted APK resource with icon name containing arbitrary path will get copied by MobSF as the icon file to the download directory which is available under `/download/` route. Fixed by https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/a58f8a8c0aa49e1581d97e19e8e2255ca96cd838
* Fixes#2324 , Bug in parsing DSA Public Key parameters for fingerprint calculation.
* Update dependencies
* Replace Android test APK
* Added tests for Library analysis from binary (scan_library route)
* iOS merge findings from swift and objective c rules with same rule identifier. Fixes#2287
* iOS Binary analysis, sort regex matches. Fixes#2252
* Framework dylibs with no extensions to skip PIE checks. Fixes#2307
* Select correct network_security config. Fixes#2049
* Android Manifest Analysis added support for detecting task hijacking (StrandHogg 1.0 and StrandHogg 2.0) . Fixes#2124
* Added new manifest analysis rule to warn on apps targeting older Android OS
* Updated severity of findings
* UI improvement for AppSec dashboard to show a loader
* UI changes in Static Analysis to collapse large no of files in API and Code Analysis for better real estate
* Improved certificate file analysis for android, jar, aar, and ios
* MobSF version Bump
* Scan independent library file (.so, .dylib, Framework dylib) from APK/IPA Static Analysis Report
* Library analysis refactored relative path helper for Django template.
* Re-introduced RELRO checks for Android, added Dart binary check to avoid Flutter false positives.
* Improved stripped debug symbol check for ELF and MachO using native OS tools such as nm and objdump when available.
* Merge iOS Framework and Dylib Analysis.