JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the promptExperiment handler of AiragPromptsController that allows any authenticated user to run AI prompt experiments. Low-privileged attackers can supply other users' prompt template and dataset ids to trigger large language model evaluation runs, write result rows into airag_ext_data, and change dataset status.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg jeecg-boot
Jeecgboot Jeecgboot jeecgboot |
|
| Vendors & Products |
Jeecg jeecg-boot
Jeecgboot Jeecgboot jeecgboot |
Sat, 10 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the promptExperiment handler of AiragPromptsController that allows any authenticated user to run AI prompt experiments. Low-privileged attackers can supply other users' prompt template and dataset ids to trigger large language model evaluation runs, write result rows into airag_ext_data, and change dataset status. | |
| Title | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/experiment | |
| First Time appeared |
Jeecg
Jeecg jeecg Boot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg
Jeecg jeecg Boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T21:49:52.621Z
Reserved: 2026-10-10T20:19:33.114Z
Link: CVE-2026-108670
No data.
Status : Received
Published: 2026-10-10T22:16:43.777
Modified: 2026-10-10T22:16:43.777
Link: CVE-2026-108670
No data.
OpenCVE Enrichment
Updated: 2026-10-11T06:15:07Z
Weaknesses