CVE-2026-35394: @mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url
(updated )
The mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android’s intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-35394 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →