What is CVE-2026-67925?
This is a Cross Site Scripting (XSS) vulnerability in JeecgBoot version 3.9.2. A remote attacker can execute arbitrary code through the '/airag/chat/upload' endpoint. It is recommended to immediately update JeecgBoot or apply the security patch provided by the vendor.
Azərbaycanca: JeecgBoot 3.9.2 versiyasında aşkar edilmiş Cross Site Scripting (XSS) zəifliyidir. Uzaqdan hücum edən şəxs '/airag/chat/upload' endpoint-i vasitəsilə ixtiyari kod icra edə bilər. Təsirə məruz qalan sistemlərdə təcili olaraq JeecgBoot-u yeniləmək və ya istehsalçı tərəfindən təqdim edilən təhlükəsizlik yamasını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which product and version does CVE-2026-67925 affect?
This vulnerability affects JeecgBoot version 3.9.2.
How can an attacker exploit CVE-2026-67925 to execute arbitrary code?
A remote attacker can execute arbitrary code through the '/airag/chat/upload' endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.