Security Flaw in Joro Web Exploitation Framework Exposes Local API
CVE-2026-53649
9.6CRITICAL
What is CVE-2026-53649?
The Joro web exploitation framework, prior to version 1.1.1, has a significant security flaw due to its default proxy mode exposing a local API. This API, accessible at 127.0.0.1:9090, does not implement any authentication and utilizes a permissive CORS policy. As a consequence, cross-origin JavaScript from any page visited by the operator can interface with sensitive endpoints, including the capability to upload plugins and trigger restarts directly from the browser without requiring preflight checks or authentication credentials. This leads to a critical risk of unauthorized remote code execution under the privileges of the operator with just a single page visit. The issue has been resolved in version 1.1.1.
Affected Version(s)
joro < 1.1.1