Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking. | |
| Title | Joyland AI WebView command injection | |
| Weaknesses | CWE-749 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T19:42:24.250Z
Reserved: 2026-09-29T16:07:07.813Z
Link: CVE-2026-102667
No data.
Status : Deferred
Published: 2026-10-01T20:17:21.750
Modified: 2026-10-01T20:31:38.333
Link: CVE-2026-102667
No data.
OpenCVE Enrichment
Updated: 2026-10-01T22:30:14Z
-
CWE-749
Exposed Dangerous Method or Function