CRITICAL 9.8 CVE-2026-75411 Published 26 Aug 2026

JeecgBoot AI Flow Groovy RCE

Worried this affects one of your servers?

JeecgBoot v3.9.2 is vulnerable to Remote command execution.

The CodeNode component of the AI Flow module supports Groovy script execution.

While the SecurityCheck class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.

Reference: CVE-2026-75411 on NVD

← Back to Security News