悟空 AICRM(截至版本号 20260610)存在一个授权缺失漏洞,允许已认证的用户通过向 POST /chat/send 接口提供任意 sessionId,写入其他用户的 AI 聊天会话。攻击者可以向受害者的对话中追加消息,并接收基于受害者最近 20 条消息生成的助手回复流,从而泄露对话内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WuKongOpenSource | Wukong AICRM | 0 ~ 20260610 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108707 | 9.8 CRITICAL | Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect |
| CVE-2026-108708 | 8.8 HIGH | Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUti |
No comments yet