CVE-2026-85639: jofpin trape Telemetry Endpoint user.py race condition
A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What deployment exposure is confirmed?
The affected component is the Telemetry Endpoint in jofpin/trape 2.0, involving unknown code in core/user.py. The available information does not establish whether this endpoint is enabled or reachable in a default deployment.
What does an attacker need to exploit this issue?
An attacker can execute the attack remotely without stated privileges or user interaction, by manipulating the vId argument. Exploitation is described as highly complex and difficult, although a public exploit has been disclosed.
Is a fix or vendor response available?
The project was notified early through an issue report but had not responded at the time of publication. No patch, workaround, or fixed version is provided in the available information.