MediumVulnerabilityLLM-specific
CVE-2026-108670: JeecgBoot missing authorization in AiragPromptsController
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108670
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
JeecgBoot through 3.9.5 has a missing authorization flaw in the promptExperiment handler of AiragPromptsController. Any authenticated user can run AI prompt experiments, including with other users' prompt template and dataset ids, which triggers LLM evaluation runs, writes result rows into airag_ext_data, and changes dataset status.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumCVE-2026-108600: open-multi-agent link following flaw in file_write tool sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108599: phi symlink escape in permission gate allows writes outside workspaceSimilar attack · NVD/CVE Database
- MediumCVE-2026-108597: Cohere Python SDK path traversal in model archive extractionSimilar attack · NVD/CVE Database
- MediumARTEX AI, Claude agents used in cyberattacks on South Korean banksSimilar attack · BleepingComputer
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News