The Joyland AI app's WebView feature accepts invalid SSL certificates by default, posing a security risk that could allow for man-in-the-middle attacks or other security risks. This CVE was published on 2026-10-01 and last modified on 2026-10-11. The vulnerability affects the Joyland AI app, particularly those managing mobile or web applications, and defenders should assess the exposure of their systems a [truncated]
CVE-2026-102669 is a vulnerability in Joyland AI where hostname checking is disabled, allowing a malicious host to connect or intercept chat messages. The CVE record was published on 2026-10-01 and last modified on 2026-10-11. The NVD entry is currently Unverified. Defenders should assess exposure to untrusted networks and verify affected versions of the app. The vulnerability has a CVSS score of 5.3 and [truncated]