CVE-2026-108665: JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/edit
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController edit handler that allows any authenticated user to modify AI prompt templates. Low-privileged attackers can send PUT or POST requests to /airag/prompts/edit with a template id to overwrite prompt text and model parameters created by administrators or other users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged user, can exploit it. The attacker does not need administrator privileges but must be able to send PUT or POST requests to the affected endpoint.
What can an attacker change?
An attacker can supply a template ID to overwrite AI prompt text and model parameters in prompt templates created by administrators or other users. The issue affects the /airag/prompts/edit handler.
Are unauthenticated deployments affected?
The available information indicates authentication is required. There is no indication that an unauthenticated attacker can exploit the issue.