CVE-2026-82880 PUBLISHED

YaCy Search Server through 1.941 XML External Entity Injection via Parsers

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor yacy
Product yacy_search_server
Versions Default: unaffected
  • affected from 0 to 1.941 (incl.)
  • Version 3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44 is unaffected

Credits

  • Yu Sun finder

References

Problem Types

  • Improper Restriction of XML External Entity Reference CWE