criticalCVSS 9.6Vulnerability

CVE-2026-53649

# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0) **Severity:** Critical **CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) **Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS **Reporter:** cstover **Date:** 2026-05-27 --- ## Summary Joro's default proxy mode (in versions <= 1.1.0) exposes a local API on `127.0.0.1:9090` that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted `multipart/form-data` content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin and triggering a restart - directly through the operator's browser, with no preflight or credentials. Since plugins execute on load, this yields unauthenticated remote code execution as the operator's user from a single page visit. --- ## Root Cause Three weaknesses combined into the exploit chain. **1. No authentication in proxy mode.** `internal/api/server.go` applied `AuthMiddleware` only when `listenerMode` was `true`. In the default proxy mode every API endpoint — including plugin upload and system restart — accepted requests without any token, cookie, or credential. **2. Permissive CORS with an insufficient protection assumption.** `corsMiddleware` set `Access-Control-Allow-Origin: *` unconditionally on all responses. `SECURITY.md` documented this as an intentional tradeoff on the basis that proxy mode binds to `127.0.0.1`, which the document states "limits exposure to the local machine." That assumption was incorrect. `multipart/form-data` is a CORS-safelisted `Content-Type`, so cross-origin JavaScript can POST files to the Joro API without triggering a preflight request — the browser allows it. Any web page the operator visited reached the localhost API through their browser without restriction. The localhost bind provided no protection against browser-mediated requests. **3. Plugin `init()` executed on `plugin

Properties

ghsa_id
GHSA-xqhv-chqm-fhcc
severity
critical
summary
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
cvss_score
9.6
cve_id
CVE-2026-53649
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-07-08T20:27:02Z
source_url
https://github.com/advisories/GHSA-xqhv-chqm-fhcc
ghsa_updated
2026-07-08T20:27:04Z

Related Entities (7)

VULNERABLE_TO (1)

[Software]go/github.com/BishopFox/joro

AFFECTS (1)

[Software]go/github.com/BishopFox/joro

HAS_WEAKNESS (4)

[Weakness]Missing Authentication for Critical Function
[Weakness]Cross-Site Request Forgery (CSRF)
[Weakness]Permissive Cross-domain Security Policy with Untrusted Domains
[Weakness]Unrestricted Upload of File with Dangerous Type

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-53649 (CVSS 9.6) — Ninja Signal Threat Intelligence | Ninja Signal