JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 21:16
Updated : 2026-09-01 19:17
NVD link : CVE-2026-75411
Mitre link : CVE-2026-75411
CVE.ORG link : CVE-2026-75411
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
