Impact
The Joyland AI app fails to verify hostnames during connection establishment, allowing a malicious host to impersonate the server and intercept or modify chat messages. This flaw falls under CWE‑297 and can lead to plain‑text message disclosure, integrity compromise, and potential for further attacks if the attacker can influence content sent to users.
Affected Systems
The vulnerability applies to Joyland:Joyland.ai software. No specific version numbers are listed, indicating that all supported releases may be impacted until a patch is released by the vendor.
Risk and Exploitability
With a CVSS score of 6.9 the risk is moderate, and the EPSS score is not available. TheISA’s KEV catalog. The likely attack vector is remote; an adversary can launch a host that responses to the same DNS name or redirect traffic to a spoofed server. No system privileges or malware execution are required, so the exploitation conditions are low. The potential impact is the disclosure and tampering of user messages, which can compromise confidentiality and integrity.
OpenCVE Enrichment