PT-2026-98562 · Rojo · Rojo

·

CVE-2026-97875

·

Published

2026-06-02

·

Updated

2026-09-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rojo (affected versions not specified)
Description The rojo serve command starts an unauthenticated HTTP API on localhost (default port 34872) that lacks Host or Origin header validation. This allows an attacker to use DNS rebinding—a technique that tricks a browser into thinking a malicious domain is actually a local address—to bypass CORS policies. A malicious webpage can then interact with the API without further user interaction to read the full project source via the /api/rojo and /api/read/{id} endpoints, write arbitrary Lua code to project files on disk using the /api/write endpoint, or launch local programs by calling the opener::open() function through the /api/open/{id} endpoint.
Recommendations Update Rojo to the version that includes the fix from pull request #1270. As a temporary mitigation, restrict the use of the rojo serve command or ensure the server is not accessible via non-loopback addresses.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97875
RUSTSEC-2026-0279

Affected Products

Rojo