Joyland AI 应用中硬编码了个推(GeTui)推送通知服务的凭据,这使得攻击者能够访问个推 REST API,并向该应用的任意单个用户、用户组或所有用户一次性发送包含任意内容的推送通知。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Joyland | Joyland.ai | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102667 | 8.3 HIGH | Joyland AI WebView command injection |
| CVE-2026-102668 | 5.3 MEDIUM | Joyland AI accepts TLS certificates without validation |
| CVE-2026-102671 | 5.3 MEDIUM | Joyland AI WebView accepts invalid SSL certificates |
| CVE-2026-102669 | 5.3 MEDIUM | Joyland AI hostname checking disabled |
| CVE-2026-102670 | 4.3 MEDIUM | Joyland AI enables HTTP |
No comments yet