CVE-2024-43399
Python vulnerability analysis and mitigation

Overview

Mobile Security Framework (MobSF), a pen-testing and malware analysis tool, was found to contain a critical vulnerability (CVE-2024-43399) with a CVSS score of 9.8. The vulnerability affects all versions up to and including 4.0.6 and was discovered in the Static Libraries analysis section, specifically in the handling of .a extension files (NVD, SecurityOnline).

Technical details

The vulnerability stems from an improperly implemented mitigation technique designed to prevent Zip Slip attacks in the Static Analyzer's handling of .a extension files. The flaw is located in the mobsf/StaticAnalyzer/views/common/shared_func.py file, where the replace operation intended to neutralize dangerous file paths can be bypassed using specially crafted sequences like ....//....//....//.. This bypass allows an attacker to escalate the file path to higher directory levels (SecurityOnline, GitHub Advisory).

Impact

The vulnerability allows attackers to extract files to any desired location within the server running MobSF. This could lead to total system compromise through the ability to overwrite critical files. A proof of concept demonstrated the ability to overwrite the MobSF database located at /home/mobsf/.MobSF/db.sqlite3, rendering the platform unusable. More malicious actions, including achieving Remote Code Execution (RCE) by overwriting essential binaries or the /etc/passwd file, are possible (SecurityOnline).

Mitigation and workarounds

The vulnerability has been patched in MobSF version 4.0.7. Users of affected versions (4.0.6 and earlier) are strongly urged to update to the latest version immediately (ASEC, NVD).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67511CRITICAL9.6
  • PythonPython
  • cai-framework
NoNoDec 11, 2025
CVE-2025-13780CRITICAL9.1
  • PythonPython
  • pgadmin4
NoYesDec 11, 2025
CVE-2025-67644HIGH7.3
  • PythonPython
  • langgraph-checkpoint-sqlite
NoYesDec 11, 2025
CVE-2025-67720MEDIUM6.5
  • PythonPython
  • pyrofork
NoYesDec 11, 2025
CVE-2025-67485MEDIUM5.3
  • PythonPython
  • mad-proxy
NoNoDec 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management