The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once. | |
| Title | Joyland AI hard-coded credentials for push notifications | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T19:41:54.776Z
Reserved: 2026-09-29T16:06:57.974Z
Link: CVE-2026-102666
No data.
Status : Deferred
Published: 2026-10-01T20:17:21.610
Modified: 2026-10-01T20:31:38.333
Link: CVE-2026-102666
No data.
OpenCVE Enrichment
Updated: 2026-10-01T22:00:17Z
Weaknesses