Executive brief
Joro, a proxy and collaboration tool, contains a vulnerability in its default configuration that allows an attacker to take over an operator's computer. By tricking a user into visiting a malicious website, the attacker can bypass security controls to upload and execute malicious code on the user's system. This could lead to full system compromise, data theft, or unauthorized access to the operator's network.
Technical details
Joro (versions <= 1.1.0) suffers from a remote code execution chain in its default proxy mode. The local API (127.0.0.1:9090) lacks authentication and implements a wildcard CORS policy. Because 'multipart/form-data' is a CORS-safelisted content type, an attacker can use cross-origin JavaScript to POST a malicious native plugin to the '/api/v1/plugins/upload' endpoint without triggering a preflight request. The attacker then triggers a system restart via the API, causing the application to load the plugin and execute its 'init()' function. This allows for unauthenticated RCE as the operator's user. The fix involves removing wildcard CORS, implementing same-origin guards using 'Sec-Fetch-Site' and 'Origin' headers, and strictly binding the API to the loopback interface.
Affected products
- BishopFox Joro <= v1.1.0
Timeline
- 2026-05-27: disclosed: Vulnerability reported by cstover
- 2026-06-01: patched: Fixes committed to repository
- 2026-07-08: advisory: GitHub Advisory published