CVE-2026-85639 PUBLISHED

jofpin trape Telemetry Endpoint user.py race condition

Assigner: VulDB
Reserved: 04.09.2026 Published: 04.09.2026 Updated: 04.09.2026

A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.3

Product Status

Vendor jofpin
Product trape
Versions
  • Version 2.0 is affected

Credits

  • GalaxynX (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Race Condition CWE