在 jofpin trape 2.0 中检测到一个安全漏洞。该漏洞影响组件 Telemetry Endpoint 中 文件内的未知代码。对该文件参数 的操作会导致竞态条件(race condition)。该攻击可远程执行。此类攻击性质复杂,可利用性较高但实现难度较大。该漏洞的利用方式已公开披露,可能被利用。项目方已提前通过问题报告获知此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85638 | 7.3 HIGH | jofpin trape user.py authorization |
| CVE-2026-85636 | 5.3 MEDIUM | jofpin trape Login Endpoint stats.py missing authentication |
| CVE-2026-85637 | 5.3 MEDIUM | jofpin trape Admin Endpoint sockets.py join_room missing authentication |
No comments yet