Impact
The Joyland AI application accepts TLS certificates presented by any server without performing validation, allowing an attacker to present a self‑signed or otherwise fraudulent certificate and establish a trusted connection. This flaw does not enable arbitrary code execution, but it permits an attacker to intercept or alter data transmitted between the application and a remote server, compromising confidentiality and potentially integrity. The weakness is identified as CWE‑295, illustrating improper handling of certificate trust.
Affected Systems
The affected product is Joyland AI, released by Joyland. Specific version information is not listed, so all current releases are potentially impacted until a fix that enforces certificate validation is applied.
Risk and Exploitability
With a CVSS base score of 6.9 the vulnerability is considered moderate and could be exploited by any adversary who can direct the application to connect to a server under their control. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain, but the accidental use of an untrusted server or a malicious internal actor could exploit the flaw in a production environment.
OpenCVE Enrichment