Improper Handling of Highly Compressed Data (Data Amplification) Affecting mobsf package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-MOBSF-10345078
  • published12 Jun 2025
  • disclosed5 May 2025
  • creditShail Shah

Introduced: 5 May 2025

CVE-2025-46730  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

mobsf is a Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) through the ZIP file upload functionality. An attacker can exhaust the server's disk space, leading to a complete denial of service for MobSF and potentially other applications or websites hosted on the same server by crafting a specially prepared ZIP file that expands significantly upon extraction.

References

CVSS Base Scores

version 4.0
version 3.1