Rojo · Rojo · CVE-2026-97875
**Name of the Vulnerable Software and Affected Versions**
Rojo (affected versions not specified)
**Description**
The `rojo serve` command starts an unauthenticated HTTP API on localhost (default port 34872) that lacks `Host` or `Origin` header validation. This allows an attacker to use DNS rebinding—a technique that tricks a browser into thinking a malicious domain is actually a local address—to bypass CORS policies. A malicious webpage can then interact with the API without further user interaction to read the full project source via the `/api/rojo` and `/api/read/{id}` endpoints, write arbitrary Lua code to project files on disk using the `/api/write` endpoint, or launch local programs by calling the `opener::open()` function through the `/api/open/{id}` endpoint.
**Recommendations**
Update Rojo to the version that includes the fix from pull request #1270.
As a temporary mitigation, restrict the use of the `rojo serve` command or ensure the server is not accessible via non-loopback addresses.