Missing Authentication in jofpin trape Admin Endpoint
CVE-2026-85637
Key Information:
Badges
What is CVE-2026-85637?
A security vulnerability has been identified in jofpin trape affecting versions 1.0.0 and 2.0. This flaw is located in the 'join_room' function of the 'core/sockets.py' component, which lacks sufficient authentication controls. As a consequence, an attacker may exploit this weakness to gain unauthorized access remotely. Despite the project's early awareness of the issue through an issue report, there has been no response or patch provided as of yet. The potential for exploitation remains, underscoring the need for immediate awareness and remediation.
Affected Version(s)
trape 1.0.0
trape 2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
