Sceawere
Vulnerability Detail
CVE-2026-104459UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Server-Side Request Forgery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST a crafted actor_handle with a numeric host and port to the abonnements view to probe internal HTTPS services and ports.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-02T12:17:17.973Z",
"pubdate": "2026-10-02T12:17:17.973Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability residing within the WebfingerService component.\nThe vulnerability allows an unauthenticated, remote attacker to influence the application to perform unauthorized HTTPS requests directed at internal network infrastructure.\nBy submitting a crafted actor_handle payload to the abonnements view, an attacker can effectively bypass perimeter security controls to probe internal hosts, discover active services, and map internal network topologies.\nThe risk implication is significant as it permits interaction with services that are otherwise not exposed to the public internet, potentially leading to unauthorized access to internal APIs or sensitive local resources.\nSuccessful exploitation requires no prior authentication or specific user privileges, making it a critical threat to the confidentiality and integrity of the internal network segment hosting the application.",
"technicalDetails": "The vulnerability is located in the WebfingerService component of YesWiki, which fails to adequately sanitize or validate the input parameters provided by users before processing them as identifiers for service lookups.\nThe primary attack vector involves the abonnements view, which accepts a POST request containing an actor_handle parameter. This parameter is intended to resolve identities, but due to insufficient input validation, it can be manipulated to accept arbitrary hostnames and port numbers.\nAn attacker can exploit this by crafting a payload where the actor_handle contains a numeric host IP and an associated port. When the WebfingerService processes this request, it initiates an outbound HTTPS connection to the specified target. Because the request originates from the server hosting the YesWiki application, it effectively circumvents firewalls or access control lists that restrict external access to internal network resources.\nThe attack flow follows these steps: 1) The attacker identifies the reachable abonnements endpoint. 2) The attacker submits a specially crafted POST request with a malicious actor_handle pointing to an internal IP address and a specific TCP port (e.g., 127.0.0.1:8080 or a sensitive internal service). 3) The WebfingerService component, acting as a proxy, attempts to reach the specified destination via HTTPS. 4) The server processes the response or returns an error based on the accessibility of the internal port, thereby revealing the status of the service to the attacker.\nThis behavior allows for network reconnaissance and port scanning from within the internal network perimeter. The lack of an allowlist for destination hosts or port restrictions allows the attacker to probe various internal resources. The impact includes the potential to interact with internal-only applications, sensitive service endpoints, or to perform man-in-the-middle operations if the internal services do not properly authenticate incoming requests. Since this vulnerability is present in versions before 4.6.7 and requires no authentication, it represents a significant security oversight in the application's request-handling logic."
}