Cross-site Scripting Flaw in YaCy Search Server by YaCy
CVE-2026-24824

6.9MEDIUM

Key Information:

Vendor

Yacy

Vendor
CVE Published:
27 January 2026

What is CVE-2026-24824?

A Cross-site Scripting (XSS) vulnerability exists in the YaCy search server due to improper neutralization of user input during web page generation. This flaw could allow an attacker to inject malicious scripts, which may be executed in the context of other users' sessions, potentially leading to data theft or unauthorized actions. The vulnerability stems from the handling of input within the YaCyDefaultServlet.Java program files of the yacy_search_server product. It is crucial for users of YaCy to implement the available patches and safeguard their applications from this risk.

Affected Version(s)

yacy_search_server 0 <= 1.92

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TITAN Team (titancaproject@gmail.com)
.