Cross-site Scripting Flaw in YaCy Search Server by YaCy
CVE-2026-24824
6.9MEDIUM
What is CVE-2026-24824?
A Cross-site Scripting (XSS) vulnerability exists in the YaCy search server due to improper neutralization of user input during web page generation. This flaw could allow an attacker to inject malicious scripts, which may be executed in the context of other users' sessions, potentially leading to data theft or unauthorized actions. The vulnerability stems from the handling of input within the YaCyDefaultServlet.Java program files of the yacy_search_server product. It is crucial for users of YaCy to implement the available patches and safeguard their applications from this risk.
Affected Version(s)
yacy_search_server 0 <= 1.92
