CVE-2026-33989Disclosure(mobilenexthq / mobile_mcp)

LOWCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for mobilenexthq mobile_mcp systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed directly to filesystem operations without validation, allowing an attacker to write files outside the intended workspace. Version 0.0.49 fixes the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mobile_mcp

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-28)
  • 4 total mentions across 2 days

Affected systems

Products
mobile_mcp

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-27: 1Mentions · 2026-03-28: 3Active Exploitation · 2026-03-28: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 203-2703-28
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-283
Active Exploitation1Disclosure2
Full discourse4 posts
  • Abhi@AbhiTheModder
    Disclosure

    Excited to share that I've got my first-ever CVE 🥳 I found a High-Severity Path Traversal vulnerability (CVE-2026-33989) in [@]mobilenext/mobile-mcp (60k+ monthly downloads). https://qbtau.in/posts/cve-2026-33989/ #CyberSecurity #Infosec #CVE #AppSec #MCP

    Post summary

    The post announces the discovery of a high‑severity path traversal vulnerability (CVE‑2026‑33989) in the mobilenext mobile‑mcp app, without detailing PoC code, exploitation, or mitigation.

    20030126
    93 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting mobile-next mobile-mcp (CVE-2026-33989) https://vuldb.com/vuln/354065/cti

    Post summary

    CTI team reports widespread exploitation activity against CVE-2026-33989 on mobile-next mobile-mcp.

    0000061
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33989 Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerabili… https://www.cve.org/CVERecord?id=CVE-2026-33989

    Post summary

    The text reports a Path Traversal vulnerability (CVE-2026-33989) in Mobile Next’s MCP server prior to version 0.0.49, but provides no PoC, exploit, patch, or evidence of ongoing exploitation.

    0000079
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33989 - High Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_sc... https://www.thehackerwire.com/vulnerability/CVE-2026-33989/ https://t.co/XHhxcWxhxp

    Post summary

    The tweet announces a Path Traversal vulnerability in @mobilenext/mobile-mcp before v0.0.49 and links to additional coverage.

    0000055
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmobilenexthqmobile_mcp-node.js-

Explore more