<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>YaCy Search Server (&lt;= 1.941) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/yacy-search-server--1.941/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 12:00:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/yacy-search-server--1.941/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-82880: XML External Entity Injection in YaCy Search Server</title><link>https://feed.craftedsignal.io/briefs/2026-08-yacy-xxe/</link><pubDate>Mon, 31 Aug 2026 12:00:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-yacy-xxe/</guid><description>YaCy Search Server through 1.941 is vulnerable to XML external entity (XXE) injection, allowing attackers to exfiltrate local files into the searchable index.</description><content:encoded><![CDATA[<p>YaCy Search Server versions up to 1.941 contain a critical XML external entity (XXE) injection vulnerability. The flaw exists within the application's SVG, FreeMind, and OpenSearch document parsers, which fail to properly disable external entity resolution during processing. An attacker can exploit this by uploading or submitting a crafted malicious document containing a DOCTYPE declaration with a SYSTEM entity that references local files. When the YaCy crawler processes these documents, it interprets the malicious entity, resolves the reference to the local file system, and includes the contents of the targeted files within the search index. This results in the exposure of sensitive local files via the search interface, effectively allowing for unauthorized data access and potential exfiltration.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized access to arbitrary files on the system hosting the YaCy Search Server. Exposure of sensitive configuration files, credentials, or system data through the searchable index poses a high risk to organizational data confidentiality.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to a version of YaCy Search Server beyond 1.941 that addresses the insecure XML parser configuration.</li>
<li>Review the searchable index for suspicious or unexpected file content that may indicate exploitation attempts.</li>
<li>Apply the principle of least privilege to the account running the YaCy process to limit access to sensitive files on the host system.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>