CVE-2026-53649Critical· 9.6▾ MidnightJoro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelis…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin and triggering a restart - directly through the operator's browser, with no preflight or credentials. Since plugins execute on load, this yields unauthenticated remote code execution as the operator's user from a single page visit. This issue has been patched in version 1.1.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/BishopFox/joro < 0.0.0-20260601151442-5c0ca35db828Patched in:
github.com/BishopFox/joro 0.0.0-20260601151442-5c0ca35db828Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34227High· 8.8Sliver is a command and control framework that uses a custom Wireguard netstack
CVE-2026-46409Critical· 9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top
CVE-2026-59148High· 8.8Mockoon provides way to design and run mock APIs
CVE-2026-34200High· 7.5Nhost is an open source Firebase alternative with GraphQL
CVE-2026-49827Critical· 9.8WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry
CVE-2026-50025Medium· 6.9Mousehole is a background service to update a seedbox IP for MAM and web app to manage it