Security Flaw in Joro Web Exploitation Framework Exposes Local API
CVE-2026-53649

9.6CRITICAL

Key Information:

Vendor

Bishopfox

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-53649?

The Joro web exploitation framework, prior to version 1.1.1, has a significant security flaw due to its default proxy mode exposing a local API. This API, accessible at 127.0.0.1:9090, does not implement any authentication and utilizes a permissive CORS policy. As a consequence, cross-origin JavaScript from any page visited by the operator can interface with sensitive endpoints, including the capability to upload plugins and trigger restarts directly from the browser without requiring preflight checks or authentication credentials. This leads to a critical risk of unauthorized remote code execution under the privileges of the operator with just a single page visit. The issue has been resolved in version 1.1.1.

Affected Version(s)

joro < 1.1.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.