Skip to main content
Vulnerability Database/CVE-2026-104465

CVE-2026-104465: YesWiki Reflected XSS Vulnerability

CVE-2026-104465 is a reflected XSS flaw in YesWiki that allows unauthenticated attackers to inject malicious scripts via the mail handler field parameter. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-104465 Overview

CVE-2026-104465 is a reflected cross-site scripting (XSS) vulnerability in YesWiki versions prior to 4.6.7. The flaw exists in the mail handler, where the field parameter is reflected into the action attribute of the ajax-mail-form HTML element without adequate sanitization. Unauthenticated attackers can craft a malicious URL whose field value breaks out of the attribute context and executes arbitrary JavaScript in the victim's browser. The vulnerability is classified under [CWE-79] (Improper Neutralization of Input During Web Page Generation).

Critical Impact

Attackers can execute arbitrary JavaScript in a victim's browser session on the YesWiki domain, enabling session theft, phishing, or forced actions against the wiki.

Affected Products

  • YesWiki versions prior to 4.6.7
  • YesWiki mail handler component (ajax-mail-form)
  • Any site deploying a vulnerable YesWiki instance exposed to untrusted users

Discovery Timeline

  • 2026-10-02 - CVE-2026-104465 published to the National Vulnerability Database
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-104465

Vulnerability Analysis

The vulnerability resides in YesWiki's mail handler, which generates an HTML form element identified as ajax-mail-form. The handler accepts a field query parameter and reflects its value directly into the form's action attribute. YesWiki fails to properly encode or validate the reflected value before rendering it.

An attacker who controls the field parameter can inject a payload containing a quote character to terminate the action attribute. The attacker can then append additional attributes such as inline event handlers that execute JavaScript when the page loads or when the user interacts with the form.

Because the attack is reflected and requires no authentication, exploitation only requires that a target user clicks or is redirected to a crafted URL pointing at a vulnerable YesWiki instance. Successful exploitation runs script in the context of the YesWiki origin, giving the attacker access to session cookies, authenticated API requests, and the ability to manipulate wiki content on behalf of the victim.

Root Cause

The root cause is insufficient output encoding of user-controlled input placed inside an HTML attribute. The mail handler trusts the field parameter and interpolates it into the ajax-mail-formaction attribute without applying context-aware escaping, allowing attribute-boundary escape and script injection.

Attack Vector

Exploitation is network-based and requires user interaction. An attacker distributes a crafted link, for example through phishing email, chat, or a malicious page, that targets the vulnerable mail handler endpoint with a weaponized field parameter. When the victim loads the URL, the injected script executes in the browser against the YesWiki origin.

No proof-of-concept exploit code is published in the referenced advisories. For technical specifics, consult the GitHub Security Advisory GHSA-2fc6-rvp3-fgfj and the VulnCheck Advisory: YesWiki XSS.

Detection Methods for CVE-2026-104465

Indicators of Compromise

  • Web server access logs containing requests to the YesWiki mail handler with a field parameter that includes quote characters, angle brackets, or event-handler strings such as onerror=, onload=, or onclick=.
  • Unexpected outbound requests from user browsers to attacker-controlled domains following access to a YesWiki URL.
  • Session cookie reuse from unfamiliar IP addresses or user agents shortly after a user visited a crafted link.

Detection Strategies

  • Deploy a web application firewall rule that inspects the field query parameter on YesWiki endpoints and blocks requests containing HTML or JavaScript metacharacters.
  • Enable a strict Content Security Policy and alert on CSP violation reports originating from the YesWiki domain.
  • Review historical access logs for the mail handler endpoint and flag requests whose field value does not match expected form field identifiers.

Monitoring Recommendations

  • Alert on anomalous HTTP 200 responses to mail handler requests where the query string length exceeds a baseline for legitimate traffic.
  • Monitor browser error telemetry and endpoint protection logs for script execution events tied to the YesWiki origin.
  • Track user reports of unexpected pop-ups, redirects, or forced form submissions on wiki pages.

How to Mitigate CVE-2026-104465

Immediate Actions Required

  • Upgrade all YesWiki installations to version 4.6.7 or later without delay.
  • Audit web server logs for prior exploitation attempts targeting the field parameter of the mail handler.
  • Rotate active session tokens and prompt users to re-authenticate after upgrading.

Patch Information

The maintainers fixed the issue in YesWiki 4.6.7. Review the GitHub Security Advisory GHSA-2fc6-rvp3-fgfj for the official patch references and version metadata.

Workarounds

  • Restrict access to the YesWiki mail handler endpoint using network ACLs or reverse-proxy rules until the upgrade is applied.
  • Deploy a web application firewall rule that rejects requests to the mail handler whose field parameter contains quote characters, angle brackets, or on*= event handler patterns.
  • Enforce a strict Content Security Policy that disallows inline scripts and limits script sources to trusted origins to reduce the impact of injected payloads.
bash
# Example nginx rule to block suspicious field parameter values on the mail handler
location ~ ^/\?.*action=mail {
    if ($arg_field ~* "[<>\"']|on[a-z]+=") {
        return 403;
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.