JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/jeecgboot/JeecgBoot/issues/9691 |
|
History
Wed, 26 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JeecgBoot Remote Command Execution via Groovy Script Injection | |
| Weaknesses | CWE-78 CWE-94 |
Wed, 26 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
Wed, 26 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-26T20:40:12.370Z
Reserved: 2026-08-17T00:00:00.000Z
Link: CVE-2026-75411
No data.
Status : Received
Published: 2026-08-26T21:16:41.097
Modified: 2026-08-26T21:16:41.097
Link: CVE-2026-75411
No data.
OpenCVE Enrichment
Updated: 2026-08-26T23:00:14Z