There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0 | Third Party Advisory |
| https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktp | Permissions Required |
Configurations
History
06 Apr 2026, 15:35
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0 - Third Party Advisory | |
| References | () https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktp - Permissions Required | |
| CPE | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| First Time |
Jeecg jeecg Boot
Jeecg |
01 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-94 |
01 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 17:16
Updated : 2026-04-06 15:35
NVD link : CVE-2024-40489
Mitre link : CVE-2024-40489
CVE.ORG link : CVE-2024-40489
JSON object : View
Products Affected
jeecg
- jeecg_boot
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
