CVE-2026-10241: jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet server-side request forgery
A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug of the component Cloud Instance Metadata Endpoint. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.9.2 mitigates this issue. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
jeecgboot/Cloud Instance Metadata Endpointto a version that resolves this vulnerability.Fixed in 3.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10241?
The severity of CVE-2026-10241 is medium with a score of 6.3.
How do I fix CVE-2026-10241?
To fix CVE-2026-10241, upgrade to JeecgBoot version 3.9.2 or later that addresses the server-side request forgery vulnerability.
What type of vulnerability is CVE-2026-10241?
CVE-2026-10241 is classified as a server-side request forgery (SSRF) vulnerability.
What component of JeecgBoot is affected by CVE-2026-10241?
CVE-2026-10241 affects the FileDownloadUtils.download2DiskFromNet function in the debug file of the Cloud Instance Metadata Endpoint.
What versions of JeecgBoot are impacted by CVE-2026-10241?
Versions of JeecgBoot up to 3.9.1 are impacted by CVE-2026-10241.