CVE-2026-108689: Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST /chat/send
Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated as a Wukong AICRM user. They can target other users' AI chat sessions by supplying an arbitrary sessionId to the POST /chat/send endpoint.
What information or access could be exposed?
An attacker can append messages to another user's conversation and receive streamed assistant responses generated using the victim's last 20 messages. This can disclose content from the victim's AI chat conversation.
How can teams determine whether they are affected?
Systems running Wukong AICRM through 20260610 are affected according to the available information. Testing should verify whether a low-privileged authenticated user can submit POST /chat/send with a sessionId belonging to a different user and receive a response based on that session's history.