Telemetry Endpoint Vulnerability in jofpin trape Software
CVE-2026-85639
Key Information:
Badges
What is CVE-2026-85639?
A security vulnerability has been identified within the jofpin trape 2.0 software that affects the telemetry endpoint feature. Specifically, the issue lies in the core/user.py file, where improper handling of the vId argument can lead to a race condition. This weakness allows an attacker to exploit the vulnerability remotely. Due to the complex nature of the exploit, it is assessed that executing such an attack may require sophisticated methods. The vulnerability was disclosed publicly, and although the development team was notified early through an issue report, no response has been issued regarding a fix at this time.
Affected Version(s)
trape 2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
