Sceawere

Vulnerability Detail

CVE-2026-85636UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Trape Missing Authentication Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
jofpin
Product
trape
Attack Type
Missing Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-04T18:18:05.300Z",
  "pubdate": "2026-09-04T18:18:05.300Z",
  "executiveSummary": "A critical security vulnerability has been identified in the jofpin trape 1.0.0 framework, specifically within the core/stats.py file associated with the Login Endpoint.\nThe vulnerability is classified as a Missing Authentication flaw, which allows unauthorized actors to bypass security controls implemented for the login process.\nThis vulnerability is remotely exploitable, requiring no prior authentication from the attacker to gain unauthorized access to sensitive statistics or internal application functionality.\nGiven that exploit code is publicly available, the risk of exploitation is significantly elevated. The absence of a vendor response to reported issues suggests that affected systems remain currently exposed to unauthorized data access and potential reconnaissance.\nImpacts include the unauthorized retrieval of application telemetry and user information, potentially facilitating further exploitation or credential harvesting operations.\nOrganizations utilizing this software version are advised to treat this as a high-priority risk and implement immediate defensive measures.",
  "technicalDetails": "The vulnerability resides in the core/stats.py module of the jofpin trape 1.0.0 platform. The defect stems from a failure to enforce authentication middleware or checks before executing the logic contained within the affected Login Endpoint component.\nTechnically, the application exposes an administrative or diagnostic function that fails to validate the identity of the requesting user. In a standard secure deployment, a login endpoint must verify session tokens or credentials before granting access to internal statistics. In this instance, the core/stats.py script processes incoming HTTP requests and returns sensitive data directly to the client without verifying the presence of a valid, authenticated session.\nThe attack flow begins with an attacker identifying the reachable endpoint associated with the stats functionality within the trape framework. The attacker sends a crafted HTTP request directly to the vulnerable URL. Because the application logic fails to perform an access control check, the server-side code in core/stats.py processes the request and executes the internal reporting functions.\nThe payload does not require specific crafting beyond standard web request formatting, as the server-side logic is fundamentally flawed in its verification process. By bypassing the expected authentication barriers, the attacker can extract internal platform statistics. This information disclosure provides adversaries with critical insight into system behavior, potentially exposing tracked user data or system configurations that could be leveraged for more advanced persistent attacks.\nBecause the component is remotely accessible and reachable over standard networking protocols (typically HTTP/HTTPS), no proximity to the server infrastructure is required. The exploit facilitates unauthorized information disclosure by design, as the application inherently trusts any request directed at the affected endpoint.\nThere is no indication of complex privilege requirements, as the vulnerability effectively nullifies the authorization layer. Post-exploitation, an attacker may use the acquired information to map system activity, identify active users, or further refine attacks against the underlying server infrastructure, significantly increasing the probability of a successful secondary compromise."
}
CVE-2026-85636: Trape Missing Authentication Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere