---
id: CVE-2026-85637
title: A security flaw has been discovered in jofpin trape 1.0.0/2.0
summary: >-
  A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by
  this issue is the function join_room of the file core/sockets.py of the
  component Admin Endpoint. The manipulation results in missing authentication.
  The attack m…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-287
  - CWE-306
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T13:12:58.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85637'
references:
  - url: 'https://github.com/jofpin/trape/'
    label: cna@vuldb.com
  - url: 'https://github.com/jofpin/trape/issues/406'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-85637'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895138'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398785'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398785/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00429
epssPercentile: 0.36771
ingestedAt: '2026-09-08T15:33:26.964Z'
---

## Overview

A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
