---
id: CVE-2026-104442
title: >-
  YesWiki before 4.6.7 contains an unauthenticated server-side request forgery
  vulnerability that allows remote attackers to make the server fetch arbitrary
  URLs by supplying a syndication action through the render handler's content
  parame…
summary: >-
  YesWiki before 4.6.7 contains an unauthenticated server-side request forgery
  vulnerability that allows remote attackers to make the server fetch arbitrary
  URLs by supplying a syndication action through the render handler's content
  parame…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-918
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:15.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104442'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-jwh5-j4f4-c6xp'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-unauthenticated-ssrf-via-syndication-action
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.337Z'
---

## Overview

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
