{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/yacy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yacy:yacy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82880"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["YaCy Search Server (\u003c= 1.941)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["YaCy"],"content_html":"\u003cp\u003eYaCy Search Server versions up to 1.941 contain a critical XML external entity (XXE) injection vulnerability. The flaw exists within the application's SVG, FreeMind, and OpenSearch document parsers, which fail to properly disable external entity resolution during processing. An attacker can exploit this by uploading or submitting a crafted malicious document containing a DOCTYPE declaration with a SYSTEM entity that references local files. When the YaCy crawler processes these documents, it interprets the malicious entity, resolves the reference to the local file system, and includes the contents of the targeted files within the search index. This results in the exposure of sensitive local files via the search interface, effectively allowing for unauthorized data access and potential exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to arbitrary files on the system hosting the YaCy Search Server. Exposure of sensitive configuration files, credentials, or system data through the searchable index poses a high risk to organizational data confidentiality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of YaCy Search Server beyond 1.941 that addresses the insecure XML parser configuration.\u003c/li\u003e\n\u003cli\u003eReview the searchable index for suspicious or unexpected file content that may indicate exploitation attempts.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to the account running the YaCy process to limit access to sensitive files on the host system.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T12:00:44Z","date_published":"2026-08-31T12:00:44Z","id":"https://feed.craftedsignal.io/briefs/2026-08-yacy-xxe/","summary":"YaCy Search Server through 1.941 is vulnerable to XML external entity (XXE) injection, allowing attackers to exfiltrate local files into the searchable index.","title":"CVE-2026-82880: XML External Entity Injection in YaCy Search Server","url":"https://feed.craftedsignal.io/briefs/2026-08-yacy-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - YaCy","version":"https://jsonfeed.org/version/1.1"}