CVE-2024-40489: Jeecg Boot
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
Affected products
- Jeecg Jeecg Boot: from 3.0, up to and including 3.5.3
Published 2026-04-01. Last modified 2026-06-17.