CVE-2026-67925: JeecgBoot JeecgBoot vulnerability
Published Aug 17, 2026
·Updated
Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload
Affected Software
1 affected component
JeecgBoot JeecgBoot=3.9.2
Event History
Aug 17, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-67925?
CVE-2026-67925 has a risk score of 52, indicating a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2026-67925?
To mitigate CVE-2026-67925, update JeecgBoot to the latest version that addresses this vulnerability.
3
What is affected by CVE-2026-67925?
CVE-2026-67925 affects JeecgBoot version 3.9.2, specifically the /airag/chat/upload endpoint.
4
What type of attack can occur due to CVE-2026-67925?
CVE-2026-67925 allows a remote attacker to execute arbitrary code on the vulnerable JeecgBoot application.
5
When was CVE-2026-67925 published?
CVE-2026-67925 was published on August 17, 2026.