JeecgBoot是中国JEECG公司开源的一个适用于企业 Web 应用程序的 Java 低代码平台。 JEECG jeecgboot 3.9.2及之前版本存在服务端请求伪造漏洞,该漏洞源于Anonymous Chat Attachment Parser组件中文件/airag/chat/send的未知函数存在服务端请求伪造问题,可能导致远程攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | JeecgBoot | 3.9.0 |
cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-19010 | 7.3 HIGH | TinyAGI Message API Endpoint index.ts processMessage authorization |
| CVE-2026-19009 | 7.3 HIGH | TinyAGI Message API Endpoint response.ts collectFiles file inclusion |
| CVE-2026-19022 | 6.3 MEDIUM | OpenHands send_pull_request.py initialize_repo command injection |
| CVE-2026-19011 | 5.3 MEDIUM | TinyAGI agents.ts buildSystemPrompt file inclusion |
| CVE-2026-19037 | 4.3 MEDIUM | WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflo |
| CVE-2026-19110 | 2.4 LOW | DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRend |
| CVE-2026-67689 | LiuCabbage FineAdmin.Mvc 安全漏洞 | |
| CVE-2026-67687 | huangjianxin1024 ics-park 安全漏洞 | |
| CVE-2026-67688 | huangjianxin1024 ics-park 安全漏洞 | |
| CVE-2024-39024 | packetfence 安全漏洞 |
No comments yet