Metrics
Affected Vendors & Products
Wed, 18 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg jeecg Boot
|
|
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:3.9.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg jeecg Boot
|
Tue, 17 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg
Jeecg jeecgboot |
|
| Vendors & Products |
Jeecg
Jeecg jeecgboot |
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generation. Executing a manipulation can lead to deserialization. The attack can be launched remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-17T15:54:22.780Z
Reserved: 2026-02-15T17:40:47.462Z
Link: CVE-2026-2555
Updated: 2026-02-17T15:53:55.930Z
Status : Analyzed
Published: 2026-02-16T12:16:22.667
Modified: 2026-02-18T21:43:53.793
Link: CVE-2026-2555
No data.