CVE-2026-97875 PUBLISHED

DNS rebinding vulnerability in rojo serve HTTP API

Assigner: redhat-cnalr
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 8.1

Product Status

Vendor rojo-rbx
Product rojo
Versions Default: unaffected
  • affected from 0 to 7.7.0 (excl.)

Credits

  • Aiden Mohan (https://github.com/AidenMohan) finder

References

Problem Types

  • CWE-350 CWE