CVE-2026-104440 UNKNOWN

CVE-2026-104440

Published: 2026-10-02

Description

YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in loadURLContent() to probe internal networks and reach internal services or metadata endpoints.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…