THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8j49-mmcx-4mp5 (medium) — MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

[GHSA] GHSA-8j49-mmcx-4mp5 (medium) — MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

highgithub_advisoriesPublished 2026-08-18

GHSA-8j49-mmcx-4mp5 Severity: medium CVE: CVE-2026-68922

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

### Summary The `find_icon_path_zip()` function in MobSF does not properly sanitize the `android:icon` attribute extracted from an Android manifest before resolving it as a filesystem path.

An attacker can supply a malicious `android:icon` value containing path trav

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8j49-mmcx-4mp5