PT-2026-83784 · Unknown · Yacy Search Server

·

CVE-2026-82880

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions YaCy Search Server versions prior to 1.942
Description An XML external entity injection issue exists in the SVG, FreeMind, and OpenSearch parsers because they fail to disable external entity resolution. This allows attackers to publish malicious documents containing DOCTYPE declarations with SYSTEM entities pointing to local files, which enables the crawler to exfiltrate the contents of those files into the searchable index.
Recommendations Update YaCy Search Server to version 1.942 or later.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82880

Affected Products

Yacy Search Server