CVE-2026-102669: Joyland AI hostname checking disabled
Published Oct 1, 2026
·Updated
Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
Affected Software
1 affected component
Joyland AI Joyland AI
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable hostname checking to verify hosts and prevent malicious hosts from connecting or intercepting chat messages.
Joyland AI app hostname checking = enabled
Event History
Oct 1, 2026
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to operate or position a malicious host that the app connects to, or be able to intercept the app's connection. No authentication or user interaction is required according to the provided vector.
2
What security impact is identified?
The issue can allow a malicious host to connect to or intercept chat messages. The reported impact is limited to integrity; no confidentiality or availability impact is specified in the provided severity vector.