Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53649— Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

Quick assessment

Affected
BishopFox joro
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joro 是一个网络利用(web exploitation)框架。在 1.1.1 版本之前,Joro 的默认代理模式会在 127.0.0.1:9090 上暴露一个本地 API,该 API 不进行身份验证,并应用了通配符 CORS 策略。由于插件上传使用的是在 CORS 中被列为安全类型的 multipart/form-data 内容类型,因此,运营者访问的任何页面上的跨域 JavaScript 都可以直接通过运营者的浏览器访问特权限定的端点——包括上传原生插件并触发重启——且无需预检请求(preflight)或凭据

CVSS 9.6 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53649

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
Source: CVE Program / CVE List V5
Vulnerability Description
Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin and triggering a restart - directly through the operator's browser, with no preflight or credentials. Since plugins execute on load, this yields unauthenticated remote code execution as the operator's user from a single page visit. This issue has been patched in version 1.1.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
BishopFox joro < 1.1.1 -

II. Public POCs for CVE-2026-53649

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53649

登录查看更多情报信息。

Other References for CVE-2026-53649 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53649

No comments yet


Leave a comment