CVE-2025-31116

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 918

Summary

CVE-2025-31116 involves a vulnerability in Mobile Security Framework (MobSF), a pen-testing and security assessment tool. The issue lies in the mitigation for a previous vulnerability, where the function valid_host() uses socket.gethostbyname() for checking valid hosts. Unfortunately, this function is susceptible to Server Side Request Forgery (SSRF) attacks using DNS rebinding techniques. As a result, unauthorized access or data exfiltration may occur. MobSF has addressed this issue in its 4.3.2 release.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share