CVE-2024-41955
Open Redirect in Opensecurity Mobile Security Framework ≤ 4.0.5
Raw vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:NCVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.
Summary
CVE-2024-41955 is a medium-severity Open Redirect (CWE-601) vulnerability in Opensecurity Mobile Security Framework. Its CVSS base score is 5.2 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Phishing (T1566); ranked in the top 40% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and AC-4 (Information Flow Enforcement) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Mobile Security Framework (MobSF) contains an open redirect vulnerability (CWE-601) in its authentication view. The flaw affects the open-source mobile application analysis platform used for Android, iOS, and Windows Mobile testing and is tracked as CVE-2024-41955 with a CVSS 3.1 score of 5.2.
An attacker with high privileges who can influence the authentication flow may supply a crafted redirect URL. When a victim user interacts with the malicious link, the browser is sent to an attacker-controlled site, enabling limited confidentiality exposure and high-integrity impacts such as phishing or session manipulation.
The project’s security advisory and associated commit recommend immediate upgrade to MobSF version 4.0.5, which contains the fix for the redirect logic. The EPSS score has remained essentially flat near 0.15 with no material post-disclosure increase.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-2299
Vulnerability Data
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V3.7.2
Mitigating Controls (NIST 800-53 r5) AI
Input validation directly checks and rejects untrusted redirect targets before they are used in a response.
Information flow enforcement can restrict redirects to only approved/trusted destinations, stopping untrusted user-supplied URLs from being followed.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require input validation and untrusted-redirect controls that prevent CWE-601.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Preventing access to attacker-controlled or malicious sites stops users from being redirected to untrusted locations via open-redirect or phishing links.