在 jofpin trape 1.0.0/2.0 中发现了一个安全漏洞。受此问题影响的是 Admin Endpoint 组件中文件 core/sockets.py 里的 join_room 函数。通过操纵该函数会导致认证缺失。攻击者可以远程发起攻击。漏洞利用代码已公开,可被用于发动攻击。项目维护方已通过问题报告提前获知该问题,但至今尚未作出响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85638 | 7.3 HIGH | jofpin trape user.py authorization |
| CVE-2026-85639 | 5.6 MEDIUM | jofpin trape Telemetry Endpoint user.py race condition |
| CVE-2026-85636 | 5.3 MEDIUM | jofpin trape Login Endpoint stats.py missing authentication |
No comments yet