Description
YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in loadURLContent() to probe internal networks and reach internal services or metadata endpoints.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Blind SSRF that enables internal network probing
Action: Apply Patch
AI Analysis

Impact

YesWiki 4.x before 4.6.7 contains a blind server‑side request forgery in the /api/entries/bazarlist endpoint. By supplying crafted values to the idtypeannonce parameter, an unauthenticated attacker can force the application to fetch arbitrary URLs. Because the input validation always accepts any string, the attacker can target internal addresses and retrieve data from intranet services or metadata endpoints, thereby bypassing network isolation.

Affected Systems

All installations of YesWiki running versions earlier than 4.6.7 are affected. The vulnerability exists in the YesWiki application (yeswiki:yeswiki). No specific sub‑product or module is singled out beyond the core API.

Risk and Exploitability

The flaw carries a CVSS score of 6.9, indicating moderate severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The exploit path is straightforward: an unauthenticated HTTP request to /api/entries/bazarlist with a manipulated idtypeannonce value. Because the application does not impose authentication or URL filtering, an attacker can probe any internal network resource reachable from the server, including cloud metadata services.

Generated by OpenCVE AI on October 2, 2026 at 12:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to YesWiki 4.6.7 or newer, where the blind SSRF is resolved.
  • If an upgrade cannot be performed immediately, restrict access to the /api/entries/bazarlist endpoint by requiring authentication or applying a firewall rule that blocks outgoing requests to internal IP ranges.
  • Implement internal network segmentation or monitoring to detect and isolate unauthorized outbound web requests from the application.

Generated by OpenCVE AI on October 2, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in loadURLContent() to probe internal networks and reach internal services or metadata endpoints.
Title YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-918
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:56:26.908Z

Reserved: 2026-10-02T00:53:03.850Z

Link: CVE-2026-104440

cve-icon Vulnrichment

Updated: 2026-10-02T14:56:03.792Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:14.837

Modified: 2026-10-02T15:17:06.893

Link: CVE-2026-104440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)