Skip to main content
Vulnerability Database/CVE-2026-104466

CVE-2026-104466: YesWiki Stored XSS Vulnerability

CVE-2026-104466 is a stored XSS flaw in YesWiki that lets attackers inject malicious JavaScript through markdown images. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-104466 Overview

CVE-2026-104466 is a stored cross-site scripting (XSS) vulnerability in YesWiki versions prior to 4.6.7. The flaw resides in formatters/wakka.php, which fails to sanitize quote characters inside markdown image URLs. Any authenticated user with permission to edit pages or post comments can inject an event handler by placing quotes in a markdown image src. The payload breaks out of the attribute and adds an onerror handler that executes JavaScript in viewers' browsers, including administrators who open the affected content. The vulnerability is tracked as CWE-79.

Critical Impact

Low-privileged contributors can store JavaScript that runs in administrator sessions, enabling account takeover of YesWiki instances through content viewing alone.

Affected Products

  • YesWiki versions before 4.6.7
  • YesWiki formatters/wakka.php markdown image parser
  • Instances allowing authenticated page editing or comment posting

Discovery Timeline

  • 2026-10-02 - CVE-2026-104466 published to NVD
  • 2026-10-02 - Last updated in NVD database

Technical Details for CVE-2026-104466

Vulnerability Analysis

YesWiki is a PHP-based collaborative wiki engine that renders markdown content through its wakka.php formatter. The formatter accepts markdown image syntax and converts it into HTML <img> tags. During this conversion, the URL supplied as the image source is placed inside the src attribute without stripping or encoding quote characters. An attacker who can submit markdown content, either by editing a page or posting a comment, can inject a crafted URL that terminates the attribute early and introduces additional HTML attributes such as onerror. When any user later views the page, the browser parses the malformed element and executes the attacker-controlled JavaScript in the context of the YesWiki origin.

Root Cause

The root cause is improper neutralization of input during web page generation inside formatters/wakka.php. The formatter trusts markdown image URLs and inserts them into HTML output without encoding quote characters that have special meaning in attribute context. This allows attribute-boundary escape and arbitrary attribute injection.

Attack Vector

Exploitation requires an account with page edit or comment privileges and relies on a victim viewing the stored content. An attacker submits a markdown image whose URL contains a quote followed by an event handler such as onerror. The persisted payload executes whenever a page viewer, including administrators, renders the content. Successful execution can hijack sessions, perform CSRF-like actions as the victim, or pivot to administrative compromise of the wiki.

For technical specifics, see the GitHub Security Advisory GHSA-7pv9-pwm8-cwwr and the VulnCheck Advisory for YesWiki XSS.

Detection Methods for CVE-2026-104466

Indicators of Compromise

  • Stored page or comment content containing markdown image syntax with embedded quote characters followed by attributes like onerror, onload, or onclick.
  • Rendered HTML in cached or exported wiki pages where <img> tags include unexpected event handler attributes.
  • Outbound requests from administrator browsers to attacker-controlled domains shortly after viewing wiki content.

Detection Strategies

  • Review the YesWiki database for stored page revisions and comments containing the substrings "onerror, 'onerror, or malformed markdown image patterns such as ![...](..."...).
  • Inspect web server access logs for POST requests to page edit and comment endpoints from low-privileged accounts preceding administrator sessions that triggered unusual activity.
  • Deploy Content Security Policy (CSP) reporting to surface inline script execution and attribute-based event handlers that violate policy.

Monitoring Recommendations

  • Monitor for anomalous session activity following administrator views of recently edited pages or newly posted comments.
  • Alert on new account creation, permission changes, or configuration modifications performed immediately after administrator page views.
  • Track egress traffic from administrator workstations to uncommon domains referenced inside wiki content.

How to Mitigate CVE-2026-104466

Immediate Actions Required

  • Upgrade all YesWiki instances to version 4.6.7 or later.
  • Audit pages and comments created or modified before patching for malicious markdown image payloads and remove any identified entries.
  • Rotate administrator session tokens and credentials that may have been exposed through viewing of attacker-controlled content.

Patch Information

The vendor fixed the vulnerability in YesWiki 4.6.7 by sanitizing quote characters within markdown image URLs before HTML output. Patch details are published in the GitHub Security Advisory GHSA-7pv9-pwm8-cwwr.

Workarounds

  • Restrict page edit and comment permissions to trusted users until the upgrade is applied.
  • Deploy a strict Content Security Policy that blocks inline event handlers and restricts script sources to the YesWiki origin.
  • Place a web application firewall rule in front of YesWiki edit and comment endpoints to reject payloads containing markdown image syntax with quote-and-handler patterns.
bash
# Example CSP header to limit XSS impact until patching completes
Content-Security-Policy: default-src 'self'; script-src 'self'; img-src 'self' data: https:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.