Impact
This vulnerability arises because YesWiki does not properly correlate the HTTP signature signer with the declared actor in the ActivityPub inbox. An unauthenticated attacker possessing any valid ActivityPub key pair can craft signed Delete or Update activities addressed to another actor’s federated entry. When the protected content’s sourceUrl is referenced, the server processes the request without verifying that the actor matches the signed key, allowing deletion or overwriting of another user’s content.
Affected Systems
Affected versions are all releases of YesWiki prior to 4.6.7; the issue has not been fixed except by upgrading to 4.6.7 or later. The product is the YesWiki content‑management platform distributed under the name yeswiki. No sub‑variant or operating‑system specifics are given, so any installation of YesWiki that includes the ActivityPub inbox before 4.6.7 is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is classified as high severity, and the EPSS score is not available. Because the flaw permits an unauthenticated actor to supply a signed request, the attack vector is remote network access; an adversary only needs to send an ActivityPub message with a fabricated signature. The flaw is listed as CWE–290 and is not present in CISA’s KEV catalog.
OpenCVE Enrichment