HIGH
rojo-rbx
CVE published 2026-09-25
CVE-2026-97875
CVE-2026-97875 debrief based on CVE Program and NVD records. The Rojo 'rojo serve' HTTP API, running on default port 34872, has a vulnerability that allows DNS rebinding attacks due to a lack of Host/Origin header validation. This could lead to unauthorized access to project source code, writing malicious code to files on disk, and launching local programs via opener::open() without user interaction. Rojo [truncated]