CVE-2025-46730 describes a "ZIP of Death" vulnerability in MobSF (Mobile Security Framework) versions up to and including 4.3.2, affecting the opensecurity mobile_security_framework product. This flaw allows an authenticated attacker to upload a specially crafted, small ZIP file that expands to an extremely large size upon extraction, leading to disk space exhaustion and a complete denial of service (DoS) for MobSF and potentially other co-hosted applications. The vulnerability carries a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring low privileges, and resulting in high impact to availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.3CPE matchmatch criteria | cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.