CVE-2026-108879 PUBLISHED

JeecgBoot through 3.9.5 IDOR via /airag/api/getChatVariable Username Parameter

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability in AiragBaseApiController that allows authenticated users to read other users' AI chat variables via the username parameter. Attackers can send POST requests to /airag/api/getChatVariable with a target appId, username, and variable name to retrieve stored chat memory values from Redis.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor jeecgboot
Product JeecgBoot
Versions Default: unaffected
  • affected from 0 to 3.9.5 (incl.)

Credits

  • Yaqi Chao finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE