CVE-2026-104461: YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField
YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST /api/entries/{formId} with SVG files containing script that executes in the wiki origin when the file is opened, enabling administrator session or account compromise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YesWikito a version that resolves this vulnerability.Fixed in 4.6.7
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who can submit a Bazar entry through the affected API endpoint can upload a crafted SVG file. Exploitation also requires someone to open the uploaded SVG in the YesWiki origin.
What is the likely impact if an administrator opens a malicious SVG?
Script embedded in the SVG can execute in the wiki origin. This can enable compromise of an administrator's session or account, and the stated impact includes low confidentiality and integrity effects across a changed scope.
Are SVG uploads protected by content sanitization in affected versions?
No. The affected Bazar FileField validates only the file extension and does not call HtmlPurifierService::cleanFile, so SVG content is stored verbatim and served inline as image/svg+xml.
How can I determine whether my deployment is affected?
Deployments running YesWiki before 4.6.7 are affected. You can also verify exposure by checking whether Bazar FileField accepts SVG uploads and stores them without invoking HtmlPurifierService::cleanFile.