THREAT OPS › Threat News › [GHSA] GHSA-8j49-mmcx-4mp5 (medium) — MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
[GHSA] GHSA-8j49-mmcx-4mp5 (medium) — MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
GHSA-8j49-mmcx-4mp5 Severity: medium CVE: CVE-2026-68922
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
### Summary The `find_icon_path_zip()` function in MobSF does not properly sanitize the `android:icon` attribute extracted from an Android manifest before resolving it as a filesystem path.
An attacker can supply a malicious `android:icon` value containing path trav
Indicators of compromise
- 6e875fb77baa9dbe65ff8e7d0344d740e1d6d51esha1
- CVE-2026-68922cve
- http://schemas.android.com/apk/res/androidurl
Original source: https://github.com/advisories/GHSA-8j49-mmcx-4mp5