Description
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Server‑Side Request Forgery
Action: Patch immediately
AI Analysis

Impact

YesWiki versions prior to 4.6.7 allow an attacker to supply arbitrary URL references in the syndication action that is processed by the render handler’s content parameter. The vulnerable code causes the server to perform an internal HTTP request to the supplied URL, exposing internal hosts and services. Successful exploitation can lead the attacker to read arbitrary network resources, and to download feed enclosures directly into the site’s files directory, potentially writing malicious files to the server. The impact is a breach of confidentiality and integrity on the affected system, without requiring any user authentication. The weakness aligns with CWE‑918, Server‑Side Request Forgery.

Affected Systems

Affected by the YesWiki content management system; any installation of YesWiki prior to version 4.6.7 is vulnerable. The product is identified by cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*.

Risk and Exploitability

The CVSS base score of 6.9 indicates a medium severity for this vulnerability. No EPSS score information is available, so the relative exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely observed in the wild. Since it requires only a crafted request to the public render endpoint and no authentication, attackers can trigger the SSRF from any network with access to the server. Without protective network or application controls, the attack can reach internal resources, read sensitive data, or write files to the web‑root.

Generated by OpenCVE AI on October 2, 2026 at 13:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply YesWiki 4.6.7 or newer to remove the SSRF flaw
  • Disable or restrict the syndication action by removing the render handler’s content parameter from publicly accessible routes
  • Implement network segmentation or firewall rules to block outbound requests from the web server to internal host ranges and unknown ports

Generated by OpenCVE AI on October 2, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.
Title YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-918
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:22:22.772Z

Reserved: 2026-10-02T00:53:03.851Z

Link: CVE-2026-104442

cve-icon Vulnrichment

Updated: 2026-10-02T15:22:02.525Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:15.153

Modified: 2026-10-02T16:16:46.237

Link: CVE-2026-104442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)