Junglewise Threat Intelligence

CVE-2026-8195: JeecgBoot XSS in SVG File Handler

CVE-2026-8195 · Severity: medium · CVSS 4.3 · Published 2026-05-09

Technologies: JeecgBoot. Vendors: JeecgBoot.

Executive brief

JeecgBoot, a low-code development platform, contains a security vulnerability in its SVG file handling component. An attacker can exploit this to perform cross-site scripting (XSS) attacks, potentially allowing them to execute malicious scripts in a user's browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in JeecgBoot versions up to 3.9.1 within the SVG File Handler component. The flaw is located in the CommonController.java file (jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java). A remote attacker can exploit this by manipulating SVG file uploads or processing, leading to the execution of arbitrary web scripts. The vulnerability is classified under CWE-79 (Cross-site Scripting) and CWE-94 (Code Injection). A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • JeecgBoot JeecgBoot up to 3.9.1

Timeline

  • 2026-05-09: disclosed: Initial public disclosure
  • 2026-05-09: advisory: NVD/VulDB advisory published

References

Related threats