Injection Vulnerability in Joyland AI App by Joyland Technologies
CVE-2026-102667

9CRITICAL

Key Information:

Vendor

Joyland

Vendor
CVE Published:
1 October 2026

What is CVE-2026-102667?

The Joyland AI app has a vulnerability that allows an attacker with shared network access to inject malicious JavaScript into content displayed in its WebView. This can lead to unauthorized access to sensitive user information, including clipboard data and the ability to make arbitrary HTTP requests through the Weex 'stream' module. Additionally, if the app has previously been granted permissions, attackers could potentially gain access to the entire file system, camera, microphone, and GPS tracking, posing significant security risks to users.

Affected Version(s)

Joyland.ai *

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincent C., CodeVispera
.