---
id: CVE-2026-104463
title: >-
  YesWiki before 4.6.7 contains a server-side request forgery vulnerability that
  allows unauthenticated attackers to trigger server requests by sending signed
  Follow activities to the public forms actor inbox route
summary: >-
  YesWiki before 4.6.7 contains a server-side request forgery vulnerability that
  allows unauthenticated attackers to trigger server requests by sending signed
  Follow activities to the public forms actor inbox route. Attackers sign
  requests…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-918
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:09.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104463'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x623-wwf6-f6wp'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-unauthenticated-ssrf-via-activitypub-inbox
    label: disclosure@vulncheck.com
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x623-wwf6-f6wp'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-02T13:39:16.298538Z'
ingestedAt: '2026-10-02T12:17:44.344Z'
---

## Overview

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching internal hosts or cloud metadata via blind GET and POST requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
