Junglewise Threat Intelligence

CVE-2026-10239: JeecgBoot SSRF in WordUtil addImage

CVE-2026-10239 · Severity: medium · CVSS 6.3 · Published 2026-06-01

Technologies: JeecgBoot. Vendors: JeecgBoot.

Executive brief

JeecgBoot, an AI-powered low-code development platform, is vulnerable to a security flaw in its Word document template processing. An attacker with basic user permissions can trick the server into making unauthorized requests to internal systems or cloud metadata services by embedding malicious links in a document template. This could allow an attacker to scan internal networks or steal sensitive credentials from the server's environment.

Technical details

A second-order (stored) Server-Side Request Forgery (SSRF) exists in JeecgBoot's Word template processing feature. The vulnerability is located in the WordUtil.addImage function within the /airag/word/edit and /airag/word/download endpoints. An attacker can inject a malicious URL into the 'main' field of a Word template via a POST/PUT request. When the template is subsequently downloaded, the server uses HttpURLConnection to fetch the image from the provided URL. The application only validates that the URL starts with 'http://' or 'https://', failing to restrict access to internal IP addresses or cloud metadata endpoints (e.g., 169.254.169.254). This allows authenticated users to perform internal port scanning or credential theft. A fix is planned for a future release.

Affected products

  • JeecgBoot JeecgBoot up to 3.9.2

Timeline

  • 2026-04-30: other: Version 3.9.2 released
  • 2026-05-06: disclosed: Issue reported on GitHub
  • 2026-06-01: advisory: CVE published

References

Related threats