CVE-2026-19000 | JeecgBoot up to 3.9.2 Anonymous Chat Attachment Parser /airag/chat/send server-side request forgery (Issue 9672)
A vulnerability identified as critical has been detected in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-19000. The attack can be initiated remotely. Additionally, an exploit exists.
A fix is planned for the upcoming release.VulDB Recent EntriesRead More