← Terug naar overzicht

A vulnerability has been identified in jofpin trape 2.0, an open-source tool used for tracking and phishing. The flaw exists in the file core/user.py, where manipulation of the vId/id arguments leads to an authorization bypass. Remote exploitation is possible without authentication, making this a significant security risk. A public exploit has already been released, increasing the likelihood of active exploitation. The project maintainer was notified via a GitHub issue but has not responded or issued a patch. The vulnerability is classified as an authorization bypass, allowing attackers to potentially access restricted resources or functionality. Given the public availability of the exploit and the lack of vendor response, users of trape 2.0 are at elevated risk.

Affected products

  • jofpin trape 2.0

Related CVE's

  • CVE-2026-85638

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities