PT-2026-83784 · Unknown · Yacy Search Server
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
YaCy Search Server versions prior to 1.942
Description
An XML external entity injection issue exists in the SVG, FreeMind, and OpenSearch parsers because they fail to disable external entity resolution. This allows attackers to publish malicious documents containing DOCTYPE declarations with SYSTEM entities pointing to local files, which enables the crawler to exfiltrate the contents of those files into the searchable index.
Recommendations
Update YaCy Search Server to version 1.942 or later.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yacy Search Server