Sceawere

Vulnerability Detail

CVE-2026-104442UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Unauthenticated SSRF Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-10-02T12:17:15.153Z",
  "pubdate": "2026-10-02T12:17:15.153Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. This security flaw originates from the application's improper handling of user-supplied input within the syndication action of the render handler.\nBy manipulating the content parameter, an unauthenticated remote attacker can coerce the web server into performing arbitrary HTTP requests to internal or external resources. This capability enables the attacker to probe internal network infrastructure, access restricted services residing behind a firewall, and potentially exfiltrate sensitive data by observing the rendered output.\nFurthermore, the vulnerability allows for the unauthorized downloading of feed enclosures directly into the server's file system. This poses a significant risk as it could lead to the storage of malicious files within the application's files directory. The vulnerability requires no prior authentication, significantly lowering the barrier for exploitation and increasing the risk profile for organizations utilizing affected versions of YesWiki.",
  "technicalDetails": "The vulnerability resides in the way YesWiki processes syndication requests via the render handler. The root cause is the lack of server-side validation and sanitization for the URL provided within the content parameter when the syndication action is invoked.\nThe attack flow begins when an unauthenticated user crafts a malicious request targeting the render handler. By supplying a specifically formatted input to the content parameter that triggers the syndication functionality, the attacker instructs the application to execute a GET request to an arbitrary destination. Because the server acts as a proxy, it can be forced to reach internal network segments, services, and ports that are otherwise protected by a perimeter firewall.\nWhen the server fetches the requested URL, it processes the response and displays the feed content directly within the rendered web page. This behavior effectively turns the YesWiki instance into a conduit for internal reconnaissance, allowing an attacker to map the internal network environment by analyzing successful and unsuccessful response patterns. Furthermore, the application's logic includes a mechanism to process feed enclosures; by pointing the content parameter to a malicious file, an attacker can force the server to download arbitrary data into the local files directory. This could potentially be leveraged for file inclusion attacks or to store malicious payloads for further exploitation stages.\nThe exploitation process is straightforward as it does not require administrative privileges or session tokens. The attacker merely needs to identify the exposed render handler endpoint and pass the URI intended for request forgery via the content parameter. The network exposure is high, as the web server is instructed to perform the network communication on behalf of the attacker, effectively bypassing Access Control Lists (ACLs) that would normally restrict the attacker's workstation from reaching internal resources. The impact is significant, encompassing information disclosure, potential remote code execution via file storage manipulation, and complete internal network mapping from the perspective of the YesWiki host."
}
CVE-2026-104442: YesWiki Unauthenticated SSRF Vulnerability (MEDIUM Severity, CVSS: 5.8) | Sceawere