CVE-2026-53649CWE-306CWE-352CWE-434CWE-942unrestricted-file-uploadcsrf

CVE-2026-53649

Critical · published September 2, 2026

CVSS v3.1
9.6
EPSS
0%
Percentile
11.8
In the wild
Unconfirmed
What it is

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin and triggering a restart - directly through the operator's browser, with no preflight or credentials. Since plugins execute on load, this yields unauthenticated remote code execution as the operator's user from a single page visit. This issue has been patched in version 1.1.1.

The record
Technical detail
CVSS v3.1
9.6 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00215 · 11.8th percentile
Weaknesses
CWE-306 · Missing Authentication for Critical Function; CWE-352 · Cross-Site Request Forgery (CSRF); CWE-434 · Unrestricted Upload of File with Dangerous Type; CWE-942 · Permissive Cross-domain Security Policy with Untrusted Domains
Published
2026-09-02T22:19Z
References (2)
EPSS history
Timeline
  • 04 SEP 03:42Z
    EPSS moved — → 0%
    epss
  • 02 SEP 17:21Z
    Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
    cvelistv5