YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side… (CVE-2026-104440)
YesWiki versions before 4.6.7 have a blind server-side request forgery (SSRF) vulnerability in the /api/entries/bazarlist endpoint. This flaw allows unauthenticated attackers to make arbitrary server-side requests by exploiting the idtypeannonce parameter. The vulnerability arises because the isValidURL() function always returns true, enabling attackers to supply internal URLs that the server fetches using curl in loadURLContent(). This can be used to probe internal networks and access internal services or metadata endpoints.
AI Analysis
Technical Summary
CVE-2026-104440 describes a blind SSRF vulnerability in YesWiki prior to version 4.6.7. The vulnerability exists in the /api/entries/bazarlist endpoint where the idtypeannonce parameter is not properly validated. The isValidURL() function incorrectly always returns true, allowing attackers to specify arbitrary internal URLs. These URLs are fetched server-side via curl in the loadURLContent() function, enabling attackers to make unauthorized requests to internal resources. This vulnerability can be exploited without authentication.
Potential Impact
The vulnerability allows unauthenticated attackers to perform blind SSRF attacks, potentially enabling them to probe internal networks and access internal services or metadata endpoints that are not otherwise accessible. The CVSS score of 5.3 (medium severity) reflects the limited impact on confidentiality (no direct data disclosure), but there is an integrity impact due to the ability to make arbitrary server-side requests. There is no impact on availability.
Mitigation Recommendations
A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. Since the vendor advisory or patch links are not provided, verify the patch availability from the official YesWiki sources before upgrading. No other mitigations are indicated.
YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side… (CVE-2026-104440)
Description
YesWiki versions before 4.6.7 have a blind server-side request forgery (SSRF) vulnerability in the /api/entries/bazarlist endpoint. This flaw allows unauthenticated attackers to make arbitrary server-side requests by exploiting the idtypeannonce parameter. The vulnerability arises because the isValidURL() function always returns true, enabling attackers to supply internal URLs that the server fetches using curl in loadURLContent(). This can be used to probe internal networks and access internal services or metadata endpoints.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104440 describes a blind SSRF vulnerability in YesWiki prior to version 4.6.7. The vulnerability exists in the /api/entries/bazarlist endpoint where the idtypeannonce parameter is not properly validated. The isValidURL() function incorrectly always returns true, allowing attackers to specify arbitrary internal URLs. These URLs are fetched server-side via curl in the loadURLContent() function, enabling attackers to make unauthorized requests to internal resources. This vulnerability can be exploited without authentication.
Potential Impact
The vulnerability allows unauthenticated attackers to perform blind SSRF attacks, potentially enabling them to probe internal networks and access internal services or metadata endpoints that are not otherwise accessible. The CVSS score of 5.3 (medium severity) reflects the limited impact on confidentiality (no direct data disclosure), but there is an integrity impact due to the ability to make arbitrary server-side requests. There is no impact on availability.
Mitigation Recommendations
A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. Since the vendor advisory or patch links are not provided, verify the patch availability from the official YesWiki sources before upgrading. No other mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-992m-5rj6-qxj2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-104440"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6abfee93a43b0b3b89e55142
Added to database: 10/02/2026, 17:49:07 UTC
Last enriched: 10/02/2026, 17:59:58 UTC
Last updated: 10/02/2026, 21:06:09 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.