{"id":"CVE-2026-97875","title":"Rojo's \"rojo serve\" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding","summary":"Rojo's \"rojo serve\" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local progr…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-350"],"vendor":"rojo-rbx","product":"rojo","affected":["rojo < 7.7.0"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T17:17:21.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97875","references":[{"url":"https://github.com/rojo-rbx/rojo/pull/1270","label":"74b3a70d-cca6-4d34-9789-e83b222ae3be"},{"url":"https://osv.dev/vulnerability/RUSTSEC-2026-0279","label":"74b3a70d-cca6-4d34-9789-e83b222ae3be"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0279.html","label":"74b3a70d-cca6-4d34-9789-e83b222ae3be"},{"url":"https://crates.io/crates/rojo"},{"url":"https://github.com/rojo-rbx/rojo/commit/ac6941f05483b0875fda52c7664cd42033db7fa2"}],"tags":["nvd","cve.org","osv","rust"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-25T16:38:52.187526Z"},"ingestedAt":"2026-09-25T11:06:38.802Z","aliases":["RUSTSEC-2026-0279"],"ecosystem":"rust","patched":["rojo 7.7.0"],"slug":"CVE-2026-97875","body":"## Overview\n\nRojo's \"rojo serve\" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-97875)\n\nAffected packages:\n\n- `rojo >= 0.0.0-0, < 7.7.0`\n\nPatched in:\n\n- `rojo 7.7.0`\n\nSource: https://osv.dev/vulnerability/RUSTSEC-2026-0279","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}