---
id: CVE-2026-85638
title: A weakness has been identified in jofpin trape 2.0
summary: >-
  A weakness has been identified in jofpin trape 2.0. This affects an unknown
  part of the file core/user.py. This manipulation of the argument vId/id causes
  authorization bypass. Remote exploitation of the attack is possible. The
  exploit h…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-285
  - CWE-639
vendor: jofpin
product: trape
affected:
  - trape 2.0
published: '2026-09-04'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:17:31.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85638'
references:
  - url: 'https://github.com/jofpin/trape/'
    label: cna@vuldb.com
  - url: 'https://github.com/jofpin/trape/issues/407'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-85638'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895139'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398786'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398786/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T20:03:25.884099Z'
epss: 0.0052
epssPercentile: 0.41814
ingestedAt: '2026-09-08T15:33:26.964Z'
---

## Overview

A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
