PatchSiren

jofpin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW jofpin CVE published 2026-09-04

CVE-2026-85639

A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult.

MEDIUM jofpin CVE published 2026-09-04

CVE-2026-85638

A weakness has been identified in jofpin trape 2.0, specifically in the file core/user.py, which allows for authorization bypass through manipulation of the argument vId/id. This vulnerability can be exploited remotely, and a public exploit is available. The project has been informed but has not yet responded. Defenders should assess exposure and verify patch status due to public exploit availability and [truncated]

MEDIUM jofpin CVE published 2026-09-04

CVE-2026-85637

A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but [truncated]

MEDIUM jofpin CVE published 2026-09-04

CVE-2026-85636

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.