Impact
The flaw exists in the join_room function of the Admin Endpoint in jofpin:trape. The endpoint omits authentication checks, allowing remote users to invoke the API and join any room without credentials, thereby gaining unauthorized access to room resources and the data they exchange.
Affected Systems
The vulnerability affects jofpin:trape versions 1.0.0 and 2.0, located in the core/sockets.py file of the Admin Endpoint component.
Risk and Exploitability
The CVSS score is 6.9, which classifies the issue as medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw can be exploited remotely, and public exploit code has already been released, meaning attackers could abuse the missing authentication if the affected systems remain exposed.
OpenCVE Enrichment