CVE-2026-108609
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Oct 10, 2026
Vendor
unknown
Description
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech input, voice settings, timestamps, and generated audio file names and paths stored in Redis.
References
- https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_airag_voice_history_read.py
- https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/voice/controller/VoiceController.java#L74-L81
- https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-idor-via-airag-voice-listbyuser-userid-parameter