CVE-2026-108673: JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/exportXls
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController exportXls handler that allows any authenticated user to export all AI prompts. Low-privileged attackers can request /airag/prompts/exportXls to download every user's prompts, including prompt content, model ids, and parameters, as an Excel workbook.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker does not need user interaction.
What data can be exposed?
The export endpoint can return all users' AI prompts in an Excel workbook, including prompt content, model IDs, and parameters.
Which deployments should be considered affected?
JeecgBoot versions through 3.9.5 are affected where the AiragPromptsController exportXls handler is available. The vulnerable request path is /airag/prompts/exportXls.