CVE 8.3 HIGH

Mobile Next has Arbitrary Android Intent Execution via mobile_open_url_CVE-2026-35394

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H

Description

Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. This vulnerability is fixed in 0.0.50.

Basic Information

ID CVE-2026-35394
Source GitHub_M
Published Apr 6, 2026 at 20:52
Modified Apr 7, 2026 at 15:09

Affected Product

Vendor mobile-next
Product mobile-mcp
Version < 0.0.50
Affected Versions mobile-next mobile-mcp < 0.0.50

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.