[CVE-2026-52769] YesWiki is a wiki system written in PHP. From version 4.6.2

CVE-2026-52769 | CVSS: 8.3 | 严重级别: HIGH

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route – exposed publicly with acl:"public" – accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature() parses the header and immediately makes a server-side HTTP GET to that URL, before any cryptographic verification or URL validation. An unauthenticated remote attacker can therefore make YesWiki issue arbitrary outbound HTTP requests to any host the server can reach – internal services, cloud-metadata endpoints (169.254.16

参考链接:
http://github.com/YesWiki/yeswiki/commit/87e627f33e79879827a3669fee2aa1244612c48
https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6
https://github.com/YesWiki/yeswiki/security/advisories/GHSA-vw42-752g-5mrp

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部