Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aiden Mohan

#34475of 57,652
8.1Total CVSS
Vulnerabilities · 1
PT-2026-98562
8.1
2026-06-02
Rojo · Rojo · CVE-2026-97875
**Name of the Vulnerable Software and Affected Versions** Rojo (affected versions not specified) **Description** The `rojo serve` command starts an unauthenticated HTTP API on localhost (default port 34872) that lacks `Host` or `Origin` header validation. This allows an attacker to use DNS rebinding—a technique that tricks a browser into thinking a malicious domain is actually a local address—to bypass CORS policies. A malicious webpage can then interact with the API without further user interaction to read the full project source via the `/api/rojo` and `/api/read/{id}` endpoints, write arbitrary Lua code to project files on disk using the `/api/write` endpoint, or launch local programs by calling the `opener::open()` function through the `/api/open/{id}` endpoint. **Recommendations** Update Rojo to the version that includes the fix from pull request #1270. As a temporary mitigation, restrict the use of the `rojo serve` command or ensure the server is not accessible via non-loopback addresses.