Executive brief
JeecgBoot, a low-code development platform, contains a security flaw in its AI Chat Module. The platform's AI assistant can be manipulated by unauthenticated remote users to perform sensitive administrative actions, such as creating new users or granting administrative roles. This could allow an attacker to gain full control over the system and its data without needing a valid login.
Technical details
A missing authentication vulnerability exists in JeecgBoot versions 3.9.0 and 3.9.1 within the AI Chat Module. The root cause is located in the 'sendWithDefault()' method of 'AiragChatServiceImpl.java', which fails to verify a user's authentication status before loading default AI tools. Because the '/airag/chat/send' endpoint is annotated with '@IgnoreAuth' to support public embedding, unauthenticated attackers can use natural language prompts to trigger sensitive business tools such as 'add_user', 'query_all_roles', and 'grant_user_roles'. This can lead to unauthorized administrative access and full system compromise. A patch has been developed to enforce authentication checks before these sensitive tools are loaded.
Affected products
- JeecgBoot JeecgBoot 3.9.0, 3.9.1
Timeline
- 2026-03-22: disclosed: Issue reported and pull request created on GitHub
- 2026-04-06: advisory: Vulnerability published to NVD
References
- https://github.com/jeecgboot/JeecgBoot/
- https://github.com/jeecgboot/JeecgBoot/commit/b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39
- https://github.com/jeecgboot/JeecgBoot/issues/9464
- https://github.com/jeecgboot/JeecgBoot/pull/9463
- https://vuldb.com/submit/785570
- https://vuldb.com/vuln/355407
- https://vuldb.com/vuln/355407/cti