Impact
Joro, a web exploitation framework, exposes a local API on 127.0.0.1:9090 when running in its default proxy mode. The API requires no authentication and allows cross‑origin requests from any origin because it uses a wildcard CORS policy. Since the plugin upload endpoint accepts the CORS‑safelisted multipart/form‑data content type, a malicious script running on any page visited by the operator can upload a native plugin and trigger a restart of the application, causing the plugin to execute as the operator’s user. This single page visit therefore yields unauthenticated remote code execution on the operator’s machine.
Affected Systems
BishopFox Joro, versions prior to 1.1.1. The vulnerability exists only when the default proxy mode is enabled and has been fixed in Joro 1.1.1.
Risk and Exploitability
The flaw carries a CVSS score of 9.6, indicating critical severity. The EPSS score is not available but the lack of authentication and the permissive CORS policy together create a straightforward local attack path. Because the exploit does not require network access besides the browser, an adversary who can execute JavaScript in the operator’s context can immediately upload and execute code. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score warrants immediate attention.
OpenCVE Enrichment
Github GHSA