LOW
YunaiV/zhijiantianya
CVE published 2026-09-24
CVE-2026-97320
A server-side request forgery vulnerability has been identified in the AI Knowledge Module of the ruoyi-vue-pro application, specifically in the AiKnowledgeDocumentServiceImpl.readUrl function. This issue allows remote attackers to manipulate the URL argument, potentially leading to unauthorized requests. The exploit has been published, and although the vendor was notified, no response was received.