Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108670: JeecgBoot missing authorization in AiragPromptsController

Identifier
CVE-2026-108670
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

JeecgBoot through 3.9.5 has a missing authorization flaw in the promptExperiment handler of AiragPromptsController. Any authenticated user can run AI prompt experiments, including with other users' prompt template and dataset ids, which triggers LLM evaluation runs, writes result rows into airag_ext_data, and changes dataset status.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.