CVE-2026-97875
8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Summary
Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rojo-rbx | rojo | 0 < 7.7.0 | affected |
Weaknesses
- CWE-350: CWE-350
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/rojo-rbx/rojo/pull/1270
- https://rustsec.org/advisories/RUSTSEC-2026-0279.html
- https://osv.dev/vulnerability/RUSTSEC-2026-0279
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.