Description
A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. A fix is planned for the upcoming release.
Problem types
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
Ana10gy (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/367518 (VDB-367518 | JeecgBoot test server-side request forgery)
vuldb.com/vuln/367518/cti (VDB-367518 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-10240 (CVE-2026-10240 | CVE Analysis and Report)
vuldb.com/submit/823267 (Submit #823267 | jeecgboot JeecgBoot <= v3.9.2 SSRF)
github.com/jeecgboot/JeecgBoot/issues/9609
github.com/jeecgboot/JeecgBoot/