Joyland AI 应用程序默认情况下会在其不可见的广告 WebView 中接受无效的 SSL 证书。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Joyland | Joyland.ai | * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Joyland | Joyland.ai | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102667 | 8.3 HIGH | Joyland AI WebView command injection |
| CVE-2026-102666 | 6.5 MEDIUM | Joyland AI hard-coded credentials for push notifications |
| CVE-2026-102668 | 5.3 MEDIUM | Joyland AI accepts TLS certificates without validation |
| CVE-2026-102669 | 5.3 MEDIUM | Joyland AI hostname checking disabled |
| CVE-2026-102670 | 4.3 MEDIUM | Joyland AI enables HTTP |
No comments yet