Authorization Flaw in JeecgBoot's AiragPromptsController Export Feature
CVE-2026-108673
Key Information:
Badges
What is CVE-2026-108673?
JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability in the AiragPromptsController's exportXls function. This flaw allows any authenticated user to export sensitive AI prompts from the system. Specifically, attackers with low privileges can access the /airag/prompts/exportXls endpoint, facilitating the unauthorized download of comprehensive prompt information, including prompt content, model identifiers, and associated parameters as an Excel file. This vulnerability poses significant risks, as it enables potential data exposure and breaches of user privacy.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
