CVE-2026-10241
Last modified
CVE-2026-10241 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug of the component Cloud Instance Metadata Endpoint. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug of the component Cloud Instance Metadata Endpoint. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.9.2 mitigates this issue. It is suggested to upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-10241?
How severe is CVE-2026-10241?
How do I fix CVE-2026-10241?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10235A flaw has been found in CodeAstro Ingredients Stock Managem…6.3
- CVE-2026-10236A vulnerability has been found in SourceCodester Water Billi…7.3
- CVE-2026-10237A vulnerability was found in SourceCodester Water Billing Ma…4.7
- CVE-2026-10238Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-10239A vulnerability was determined in JeecgBoot up to 3.9.2. The…6.3
- CVE-2026-10240A vulnerability was identified in JeecgBoot up to 3.9.2. The…6.3
- CVE-2026-10242A weakness has been identified in itsourcecode Content Manag…6.3
- CVE-2026-10243A security vulnerability has been detected in code-projects …7.3
- CVE-2026-10244A vulnerability was detected in SourceCodester Pharmacy Sale…3.5
- CVE-2026-10245A flaw has been found in SourceCodester Pharmacy Sales and I…3.5
- CVE-2026-10246A vulnerability has been found in SourceCodester Pharmacy Sa…3.5
- CVE-2026-10247A vulnerability was found in SourceCodester Pharmacy Sales a…3.5
Are you affected by CVE-2026-10241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
