A weakness has been identified in JeecgBoot 3.9.1. This...
Low severity
Unreviewed
Published
Feb 16, 2026
to the GitHub Advisory Database
•
Updated Feb 19, 2026
Description
Published by the National Vulnerability Database
Feb 16, 2026
Published to the GitHub Advisory Database
Feb 16, 2026
Last updated
Feb 19, 2026
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generation. Executing a manipulation can lead to deserialization. The attack can be launched remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The project was informed of the problem early through an issue report but has not responded yet.
References