CVE-2026-104440: YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter
YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in loadURLContent() to probe internal networks and reach internal services or metadata endpoints.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
YesWiki versions before 4.6.7 are affected. The vulnerable request path is /api/entries/bazarlist.
Does exploitation require an account or user interaction?
No. An unauthenticated attacker can exploit the issue remotely without user interaction.
What can an attacker cause the server to request?
An attacker can provide internal URLs through the idtypeannonce parameter, causing the server to fetch them with curl. This can be used to probe internal networks and access internal services or metadata endpoints.
How can I determine whether my instance is affected?
Check the installed YesWiki version. Instances running a version earlier than 4.6.7 are affected.