CVE-2026-52474

7.5

AiFlowy · AiFlowy

An information disclosure vulnerability in AiFlowy allows unauthenticated remote attackers to obtain sensitive data via JobUtil.java.

Executive summary

A critical information disclosure vulnerability in AiFlowy version 2.1.2 and prior allows unauthenticated remote attackers to harvest sensitive system information.

Vulnerability

This is an information disclosure vulnerability residing within the JobUtil.java file, permitting unauthenticated remote attackers to extract sensitive data via network vectors without requiring user interaction.

Business impact

The exposure of sensitive information can lead to unauthorized data access, potentially compromising internal system architecture, credentials, or business-critical data. Based on a CVSS score of 7.5, this high-severity flaw introduces significant risk because attackers can exploit it remotely over the network with zero privileges or user interaction required.

Remediation

Immediate Action: Restrict network access to the vulnerable application components and check vendor channels for an updated release beyond version 2.1.2.

Proactive Monitoring: Monitor network perimeter logs and application access trails for unusual requests targeting Java utility endpoints or unexpected data retrieval patterns.

Compensating Controls: Deploy Web Application Firewall rules to block suspicious HTTP requests targeting the JobUtil component and enforce strict perimeter controls.

Exploitation status

Public Exploit Available: Yes, a public technical writeup exists via the referenced GitHub advisory detailing the attack vector.

Analyst recommendation

Organizations utilizing AiFlowy versions 2.1.2 and below must treat this high-severity issue with urgency by implementing strict perimeter defenses and monitoring closely for emerging patches. Administrators should apply vendor updates immediately upon availability to eliminate the underlying information disclosure risk.

Sources