OSV 1.4.0 · unreviewed · 修改于 2026-09-02 05:31
发布时间
2026-08-27 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-27 05:16
源文件
advisories/unreviewed/2026/08/GHSA-8mm6-mrr9-hg9w/GHSA-8mm6-mrr9-hg9w.json
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the SecurityCheck class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.
该公告没有提供结构化的受影响软件包信息。