These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has be [truncated]
The CVE-2026-82629 vulnerability was identified in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This unrestricted upload vulnerability affects the MyJwWebJwid3Controller.doUpload function in the jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java file of the doUpload Endpoint. The vulnerability allows for remote exploitation. Evidence is li [truncated]
CVE-2026-75411 is a critical vulnerability in JeecgBoot v3.9.2, allowing remote command execution through Groovy script execution in the AI Flow module's CodeNode component. The SecurityCheck class employs a blacklist mechanism to intercept dangerous calls, but Groovy's dynamic nature enables bypassing this blacklist via string concatenation and reflection. Users and administrators should prioritize patch [truncated]
CVE-2026-75479 debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T21:16:50.333Z and has not been modified since then. This high-severity authentication bypass vulnerability in JimuReport allows unauthenticated attackers to enumerate reports and retrieve share tokens, potentially leading to exposure of report definitions and live query data. Defenders should prioritize [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T21:16:47.507Z and has not been modified since then. CVE-2026-67926 is a critical vulnerability in JeecgBoot v.3.9.2 AI Chat Module, allowing remote attackers to execute arbitrary code via the files Parameter. The vulnerability has a CVSS score of 9.8 and is considered critical. Affected users sho [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T21:16:47.397Z and has not been modified since then. CVE-2026-67925 is a Cross Site Scripting vulnerability in JeecgBoot v.3.9.2, allowing remote attackers to execute arbitrary code via the /airag/chat/upload endpoint. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. [truncated]
CVE-2026-19000 is a server-side request forgery vulnerability in JeecgBoot up to 3.9.2, specifically affecting the Anonymous Chat Attachment Parser component. The vulnerability is located in the /airag/chat/send file and can be exploited remotely, potentially leading to unauthorized actions on the server. Organizations should review their deployments and prepare for an upcoming fix. The CVSS score is 5.5, [truncated]
A weakness has been identified in JeecgBoot up to 3.9.2. The impacted function is HttpServletResponse.sendRedirect in the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This manipulation of the argument state causes an open redirect. The attack can be initiated remotely, but a high degree of complexi [truncated]
A vulnerability was identified in JeecgBoot up to 3.9.2. The function queryPageList in SysUserController.java is affected, allowing for information disclosure via manipulation of the 'salt' argument. The attack may be initiated remotely and has high complexity. A fix is planned for an upcoming release.
A server-side request forgery (SSRF) vulnerability in JeecgBoot, affecting versions up to 3.9.1. The flaw exists in the `FileDownloadUtils.download2DiskFromNet` function via the `/airag/app/debug` endpoint, where improper handling of URLs allows remote attackers to manipulate requests to cloud instance metadata endpoints. The vulnerability was publicly disclosed on 2026-06-01 with a CVSS 4.0 score of 2.1 [truncated]
A low-severity improper access control vulnerability affects JeecgBoot versions up to 3.9.1. The vulnerability resides in the AiragModelController component, where manipulation of the list/queryById argument can lead to unauthorized access. The issue is remotely exploitable and public exploit availability has been confirmed. The vendor has released version 3.9.2 to address this vulnerability.
A low-severity improper access control vulnerability in JeecgBoot versions up to 3.9.1 allows authenticated remote attackers to manipulate the /sys/comment/add endpoint. The vulnerability was disclosed on 2026-05-26 with a CVSS 4.0 score of 2.1 (LOW severity). An upgrade to version 3.9.2 resolves the issue. The vulnerability is classified under CWE-266 (Incorrect Privilege Assignment) and CWE-284 (Imprope [truncated]
A low-severity improper access control vulnerability in JeecgBoot versions up to 3.9.1 allows authenticated remote attackers to manipulate the userIdentity parameter in the /sys/user/login/setting/userEdit endpoint's user.getUsername function. The vulnerability, published 2026-05-26, has a CVSS 4.0 score of 2.1 (LOW severity) and has been publicly disclosed with available exploit details. The vendor has r [truncated]
A vulnerability in JeecgBoot 3.9.1 affects the OpenAPI Endpoint at /openapi/call/, where improper authentication controls allow remote attackers to bypass authentication. The attack requires high complexity and is assessed as difficult to exploit. The vendor was contacted prior to disclosure but did not respond. The vulnerability was published on 2026-05-24 and last modified on 2026-05-26.
CVE-2026-8195 is a cross-site scripting issue reported in JeecgBoot up to 3.9.1, centered on SVG file handling in CommonController.java. The CVE description says the attack can be executed remotely, that exploit material is public, and that the vendor was contacted early but did not respond. While the CVSS score is low, publicly available exploitation details increase the need to verify exposure and harde [truncated]
A medium-severity vulnerability, CVE-2026-5616, was detected in JeecgBoot versions 3.9.0 and 3.9.1. The vulnerability is located in an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java within the AI Chat Module. This vulnerability allows for missing authentication, which can be exploited remotely. The issue has bee [truncated]