Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joyland
Joyland joyland.ai |
|
| Vendors & Products |
Joyland
Joyland joyland.ai |
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking. | |
| Title | Joyland AI WebView command injection | |
| Weaknesses | CWE-749 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-02T16:49:33.992Z
Reserved: 2026-09-29T16:07:07.813Z
Link: CVE-2026-102667
No data.
Status : Deferred
Published: 2026-10-01T20:17:21.750
Modified: 2026-10-02T17:17:01.083
Link: CVE-2026-102667
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:47:52Z
-
CWE-749
Exposed Dangerous Method or Function