
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33545 is a SQL injection vulnerability in Mobile Security Framework (MobSF) affecting the read_sqlite() function in mobsf/MobSF/utils.py. The flaw allows a malicious mobile application containing a crafted SQLite database to cause denial of service or SQL injection against the MobSF analysis platform when a security analyst views the database file. All MobSF versions up to and including 4.4.5 are affected; version 4.4.6 contains the fix. The vulnerability was disclosed on March 21, 2026, and carries a CVSS v3.1 base score of 5.3–6.5 (Moderate/Medium), depending on the scoring source (GitHub Advisory, MobSF Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In mobsf/MobSF/utils.py lines 542–566, the read_sqlite() function retrieves table names from a SQLite database's sqlite_master table and interpolates them directly into SQL queries using Python's % string formatting — without parameterization or identifier escaping. Specifically, lines 553 and 557 construct PRAGMA table_info('%s') and SELECT * FROM '%s' queries with attacker-controlled table names. An attacker crafts a SQLite database with a table named x' UNION SELECT 'SQL_INJECTION_PROOF'--, which when interpolated produces syntactically malformed or injected SQL. The function is triggered from two call sites: the Dynamic Analysis File Viewer (Android and iOS) and the iOS Static Analysis File Viewer, both activated when an analyst clicks to view a .db file (GitHub Advisory, MobSF Advisory).
The primary confirmed impact is denial of service: a malicious table name causes read_sqlite() to throw a sqlite3.OperationalError, crashing the database viewer and preventing the analyst from viewing any data in the SQLite database. This can be weaponized by malicious app authors to hide incriminating content — such as C2 server URLs, stolen credentials, or API keys — from MobSF's analysis, directly undermining its core security purpose. A secondary, confirmed-in-isolation impact is SQL injection via UNION SELECT, which allows attacker-controlled data to be returned in query results; however, the current code structure (PRAGMA executing before SELECT) limits the full exploitation chain in practice (GitHub Advisory, MobSF Advisory).
A proof-of-concept exploit with step-by-step reproduction instructions, a pre-built malicious APK (malicious_sqli.apk), a crafted SQLite database (malicious.db), and a standalone PoC script (poc_sqlite_injection.py) are publicly available via Google Drive, as referenced in the GitHub Security Advisory. Exploitation requires user interaction — a security analyst must upload and then click to view the malicious database file within MobSF. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.025–0.035%, indicating low near-term exploitation probability (MobSF Advisory, GitHub Advisory).
Craft the malicious SQLite database: Create a SQLite database file containing a table with an injected name, e.g.:
CREATE TABLE "x' UNION SELECT 'SQL_INJECTION_PROOF'--" (id INTEGER);This can be done using the provided poc_sqlite_injection.py script or manually with any SQLite tool.
Package into a mobile application: Embed the crafted .db file (e.g., app_data.db) into an Android APK's assets/ directory using the provided create_malicious_apk.sh script or manually with Android SDK tools. An iOS IPA can be used similarly.
Deliver the application for analysis: Distribute or submit the malicious APK/IPA to a target security analyst who uses MobSF for mobile application analysis.
Trigger the vulnerable code path: The analyst uploads malicious_sqli.apk to MobSF and browses the extracted files. When the analyst clicks on app_data.db to view it, MobSF calls read_sqlite(), which reads table names from sqlite_master and interpolates the malicious name into SQL queries.
Achieve DoS: The PRAGMA table_info('x' UNION SELECT 'SQL_INJECTION_PROOF'--') statement raises a sqlite3.OperationalError (syntax error near "UNION"), causing read_sqlite() to return empty results — the analyst cannot view any database content, effectively hiding the app's stored data from analysis.
Achieve SQL injection (in isolation): If the PRAGMA step is bypassed or removed, the SELECT * FROM 'x' UNION SELECT 'SQL_INJECTION_PROOF'--' query executes successfully, returning attacker-controlled data in the MobSF database viewer (MobSF Advisory, GitHub Advisory).
atlassian-mobsf.log or equivalent) showing sqlite3.OperationalError: near "UNION": syntax error or similar SQL syntax errors when a .db file is viewed; log entries from logger.exception('Reading SQLite db') in mobsf/MobSF/utils.py.app_data.db) within an analyzed APK/IPA's extracted assets directory containing a table in sqlite_master with SQL metacharacters (', --, UNION, SELECT) in the table name..db file is clicked during analysis, despite the file being non-empty; repeated failures to display database content for a specific uploaded application.Upgrade MobSF to version 4.4.6 or later, which resolves the vulnerability by replacing % string formatting with properly escaped double-quoted SQL identifiers (doubling any embedded double quotes: " → ""), and also opens SQLite databases in read-only mode (file:{path}?mode=ro). The fix was committed in commit 6f8a43c and released on March 21, 2026. No configuration-based workaround is available; upgrading is the only remediation (MobSF Release v4.4.6, GitHub Advisory).
The vulnerability was reported by researcher djvirus9 and published by MobSF maintainer ajinabraham on March 21, 2026, with a same-day patch release (v4.4.6). A technical write-up was published at infinitsec.net shortly after disclosure. Community reaction on the MobSF GitHub release page was mixed, with some emoji reactions suggesting amusement at the nature of the vulnerability (a security tool being vulnerable to a malicious app it is analyzing). No significant broader media coverage or threat actor commentary has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."