Skip to main content

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by… (CVE-2026-104464)

0
High
Published: 10/02/2026 (10/02/2026, 12:31:17 UTC)
Source: GCVE Database

Description

YesWiki versions prior to 4.6.7 contain a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to make server-side GET requests by providing an unvalidated actor URL to the Bazar abonnements sync action. Exploitation can target internal hosts or cloud metadata endpoints, with attacker-controlled outbox links enabling response data to be stored as readable Bazar entries. The vulnerability has a high severity rating with a CVSS score of 8.6.

CVSS v3.1

Score 8.6high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected software

GitHub Actionsmore threats →ai
yeswiki/yeswiki
pkg:github/yeswiki/yeswiki
Affected versions
<4.6.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 17:57:35 UTC

Technical Analysis

YesWiki before version 4.6.7 is affected by a server-side request forgery vulnerability (CVE-2026-104464). The vulnerability arises from insufficient validation of actor URLs supplied to the Bazar abonnements sync action, allowing unauthenticated attackers to induce the server to perform arbitrary GET requests. Attackers can leverage this to access internal network resources or cloud metadata endpoints. Additionally, they can manipulate outbox first/next links to chain requests, with the fetched responses stored as readable Bazar entries, potentially exposing sensitive information.

Potential Impact

Successful exploitation allows unauthenticated attackers to make arbitrary server-side GET requests, potentially accessing internal hosts or sensitive cloud metadata endpoints. This can lead to information disclosure (high confidentiality impact), partial integrity compromise (low integrity impact), and partial availability impact (low availability impact) as per the CVSS vector. The vulnerability could facilitate further attacks by revealing internal network structure or credentials.

Mitigation Recommendations

A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. No additional mitigation guidance is provided in the available data. Patch status is confirmed by the version numbering indicating the fix in 4.6.7.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-ghw3-mg2w-7jg2
Osv Schema Version
1.4.0
Aliases
["CVE-2026-104464"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6abfee88a43b0b3b89e54bdd

Added to database: 10/02/2026, 17:48:56 UTC

Last enriched: 10/02/2026, 17:57:35 UTC

Last updated: 10/02/2026, 21:46:10 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses