PatchSiren

YunaiV/zhijiantianya CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW YunaiV/zhijiantianya CVE published 2026-09-24

CVE-2026-97320

A server-side request forgery vulnerability has been identified in the AI Knowledge Module of the ruoyi-vue-pro application, specifically in the AiKnowledgeDocumentServiceImpl.readUrl function. This issue allows remote attackers to manipulate the URL argument, potentially leading to unauthorized requests. The exploit has been published, and although the vendor was notified, no response was received.