Description
A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. A fix is planned for the upcoming release.
Problem types
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
Ana10gy (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/367517 (VDB-367517 | JeecgBoot edit WordUtil.addImage server-side request forgery)
vuldb.com/vuln/367517/cti (VDB-367517 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-10239 (CVE-2026-10239 | CVE Analysis and Report)
vuldb.com/submit/823266 (Submit #823266 | jeecgboot JeecgBoot <= v3.9.2 SSRF)
github.com/jeecgboot/JeecgBoot/issues/9610
github.com/jeecgboot/JeecgBoot/