CVE-2026-104464: YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled outbox first/next links, with fetched responses stored as readable Bazar entries.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker can exploit it by supplying an unvalidated actor URL to the Bazar abonnements sync action. No user interaction or prior privileges are required.
What systems or data could the vulnerable server reach?
The attacker can cause server-side GET requests to internal hosts and cloud metadata endpoints. Responses fetched through the sync action can be stored as readable Bazar entries.
Is there a known fixed version?
YesWiki versions before 4.6.7 are affected; upgrading to 4.6.7 or later addresses the affected version range described.
Can the issue be extended beyond a single request?
Yes. An attacker can chain attacker-controlled outbox first and next links, allowing the server to follow additional attacker-directed URLs during synchronization.