CVE-2026-104447: YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like bazar, breaking core site functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YesWikito a version that resolves this vulnerability.Fixed in 4.6.7
Event History
Frequently Asked Questions
Who must an attacker target to exploit this issue?
An attacker must lure a logged-in YesWiki administrator into visiting a crafted link. No attacker authentication is required, but exploitation requires administrator interaction.
What can a successful attack do to the affected site?
The attack can delete installed YesWiki packages through the autoupdate UpdateAction, including extensions such as bazar. Removing these packages can break core site functionality.
How can I determine whether a YesWiki instance is affected?
Instances running a YesWiki version before 4.6.7 are affected. The vulnerable behavior is the ability to invoke package deletion through an unprotected GET request using action=delete and a package parameter.