CVE-2026-97320 Details
Description
A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI Knowledge Module. This manipulation of the argument url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in YunaiV/zhijiantianya ruoyi-vue-pro versions through 2026.08. The issue arises in the AI Knowledge Module, specifically within the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java. The vulnerability allows remote exploitation by manipulating the 'url' argument, potentially leading to unauthorized requests being sent from the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/908270 | CISA-ADP | Issue TrackingPermission Required |
| https://vuldb.com/cve/CVE-2026-97320 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908270 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/409328 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/409328/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| YunaiV/zhijiantianya ruoyi-vue-pro | <= 2026.08 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion