LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33989

CVE-2026-33989 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 27, 2026

Mobile Next MCP - Path Traversal

Published: March 27, 2026Updated: March 27, 2026Remote Exploitable

Overview

Mobile Next MCP server < 0.0.49 contains a path traversal caused by unvalidated 'saveTo' and 'output' parameters in mobile_save_screenshot and mobile_start_screen_recording tools, letting attackers write files outside intended workspace, exploit requires no special privileges.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can write files outside the intended workspace, potentially leading to arbitrary file creation or modification.

Mitigation

Upgrade to version 0.0.49 or later.

Social Media Activity(4 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

🟠 CVE-2026-33989 - High (8.1) Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33989/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

🟠 CVE-2026-33989 - High (8.1) Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33989/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

🟠 CVE-2026-33989 - High (8.1) Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33989/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

🟠 CVE-2026-33989 - High (8.1) Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33989/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-33989
Severity
High
CVSS Score
8.1
Type
path_traversal
Status
new
EPSS
0.0%
Social Posts
4

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days