PT-2026-98562 · Rojo · Rojo
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Rojo (affected versions not specified)
Description
The
rojo serve command starts an unauthenticated HTTP API on localhost (default port 34872) that lacks Host or Origin header validation. This allows an attacker to use DNS rebinding—a technique that tricks a browser into thinking a malicious domain is actually a local address—to bypass CORS policies. A malicious webpage can then interact with the API without further user interaction to read the full project source via the /api/rojo and /api/read/{id} endpoints, write arbitrary Lua code to project files on disk using the /api/write endpoint, or launch local programs by calling the opener::open() function through the /api/open/{id} endpoint.Recommendations
Update Rojo to the version that includes the fix from pull request #1270.
As a temporary mitigation, restrict the use of the
rojo serve command or ensure the server is not accessible via non-loopback addresses.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rojo