A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | jofpin trape Telemetry Endpoint user.py race condition | |
| First Time appeared |
Jofpin
Jofpin trape |
|
| Weaknesses | CWE-362 | |
| CPEs | cpe:2.3:a:jofpin:trape:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jofpin
Jofpin trape |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-09-04T19:00:08.739Z
Updated: 2026-09-04T19:00:08.739Z
Reserved: 2026-09-04T12:19:31.197Z
Link: CVE-2026-85639
No data.
Status : Deferred
Published: 2026-09-04T19:17:33.600
Modified: 2026-09-08T13:12:58.310
Link: CVE-2026-85639
No data.