rojo
Activity
- Latest release
- 2mo ago
- Total releases
- 73
- Cadence
- ~25 days
- Last 12 months
- 4
Details
- License
- MPL-2.0
- First release
- Nov 30, 2017
| Version | Released | |
|---|---|---|
7.7.0
unknown
|
7.7.0
unknown
Dependencies (60)
+ 52 more |
|
7.7.0-rc.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.7.0-rc.1
unknown
Dependencies (57)
+ 49 more |
|
7.6.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.6.1
unknown
Dependencies (52)
+ 44 more |
|
7.6.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.6.0
unknown
Dependencies (51)
+ 43 more |
|
7.5.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.5.1
unknown
Dependencies (49)
+ 41 more |
|
7.5.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.5.0
unknown
Dependencies (49)
+ 41 more |
|
7.4.4
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.4
unknown
Dependencies (51)
+ 43 more |
|
7.4.3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.3
unknown
Dependencies (51)
+ 43 more |
|
7.4.2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.2
unknown
Dependencies (51)
+ 43 more |
|
7.4.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.0
unknown
Dependencies (51)
+ 43 more |
|
7.4.0-rc3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.0-rc3
unknown
Dependencies (52)
+ 44 more |
|
7.4.0-rc2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.0-rc2
unknown
Dependencies (52)
+ 44 more |
|
7.4.0-rc1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.4.0-rc1
unknown
Dependencies (52)
+ 44 more |
|
7.2.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.2.1
unknown
Dependencies (48)
+ 40 more |
|
7.2.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.2.0
unknown
Dependencies (48)
+ 40 more |
|
7.1.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.1.1
unknown
Dependencies (46)
+ 38 more |
|
7.1.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.1.0
unknown
Dependencies (50)
+ 42 more |
|
7.0.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0
unknown
Dependencies (50)
+ 42 more |
|
7.0.0-rc.3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-rc.3
unknown
Dependencies (50)
+ 42 more |
|
7.0.0-rc.2
unknown
yanked
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-rc.2
unknown
yanked
Dependencies (50)
+ 42 more |
|
7.0.0-rc.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-rc.1
unknown
Dependencies (50)
+ 42 more |
|
6.2.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.2.0
unknown
Dependencies (48)
+ 40 more |
|
7.0.0-alpha.4
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-alpha.4
unknown
Dependencies (49)
+ 41 more |
|
6.1.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.1.0
unknown
Dependencies (48)
+ 40 more |
|
7.0.0-alpha.3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-alpha.3
unknown
Dependencies (49)
+ 41 more |
|
7.0.0-alpha.2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-alpha.2
unknown
Dependencies (49)
+ 41 more |
|
7.0.0-alpha.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
7.0.0-alpha.1
unknown
Dependencies (49)
+ 41 more |
|
6.0.2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.2
unknown
Dependencies (48)
+ 40 more |
|
6.0.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.1
unknown
Dependencies (48)
+ 40 more |
|
6.0.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.0
unknown
Dependencies (48)
+ 40 more |
|
6.0.0-rc.4
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.0-rc.4
unknown
Dependencies (48)
+ 40 more |
|
6.0.0-rc.3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.0-rc.3
unknown
Dependencies (48)
+ 40 more |
|
6.0.0-rc.2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.0-rc.2
unknown
Dependencies (48)
+ 40 more |
|
6.0.0-rc.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
6.0.0-rc.1
unknown
Dependencies (48)
+ 40 more |
|
0.6.0-alpha.3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.6.0-alpha.3
unknown
Dependencies (39)
+ 31 more |
|
0.6.0-alpha.2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.6.0-alpha.2
unknown
Dependencies (36)
+ 28 more |
|
0.5.4
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.4
unknown
Dependencies (25)
+ 17 more |
|
0.6.0-alpha.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.6.0-alpha.1
unknown
Dependencies (36)
+ 28 more |
|
0.5.3
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.3
unknown
Dependencies (25)
+ 17 more |
|
0.5.2
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (25)
+ 17 more |
|
0.5.1
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.1
unknown
Dependencies (25)
+ 17 more |
|
0.5.0
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (25)
+ 17 more |
|
0.5.0-alpha.13
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.13
unknown
Dependencies (25)
+ 17 more |
|
0.5.0-alpha.12
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.12
unknown
Dependencies (25)
+ 17 more |
|
0.5.0-alpha.11
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.11
unknown
Dependencies (25)
+ 17 more |
|
0.5.0-alpha.10
unknown
yanked
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.10
unknown
yanked
Dependencies (25)
+ 17 more |
|
0.5.0-alpha.9
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.9
unknown
Dependencies (26)
+ 18 more |
|
0.5.0-alpha.8
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.8
unknown
Dependencies (26)
+ 18 more |
|
0.5.0-alpha.6
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.6
unknown
Dependencies (26)
+ 18 more |
|
0.5.0-alpha.5
unknown
1 CVE
RUSTSEC-2026-0279
Jun 02, 2026
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Rojo's The serve API is a two-way sync protocol. Once a DNS rebind is established, a
malicious webpage visited by a developer running
The flaw was corrected in #1270,
which adds Reported by Aiden Mohan. Fixed in
7.7.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0-alpha.5
unknown
Dependencies (27)
+ 19 more |