在 Jofpin Trape 2.0 中发现了一个安全缺陷。该问题位于 文件中的某个未知部分。通过操纵参数 或 ,攻击者可以实现权限绕过(Authorization Bypass)。该漏洞可被远程利用,且利用方法已公开,可被用于发起攻击。项目方已通过问题报告提前得知此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85639 | 5.6 MEDIUM | jofpin trape Telemetry Endpoint user.py race condition |
| CVE-2026-85636 | 5.3 MEDIUM | jofpin trape Login Endpoint stats.py missing authentication |
| CVE-2026-85637 | 5.3 MEDIUM | jofpin trape Admin Endpoint sockets.py join_room missing authentication |
No comments yet