Answer in brief
CVE-2026-108689 records a Medium severity (CVSS 5.3) vulnerability in Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST /chat/send. The current sources do not mark it as known exploited. The current feed maps WuKongOpenSource/Wukong AICRM (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WuKongOpenSource/Wukong AICRM (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WuKongOpenSource/Wukong AICRMgeneric | >=0 <=20260610 | Not reported |
Published upstream
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 11, 2026
Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content.
Quoted source text, attributed separately from HOL analysis.