Get real-time updates on Telegram
CVE-2026-107781: skyeye affected git revisions
CVE-2026-107781. CVSS 3.1 base score 7.4 (GitHub Advisory Database).
Affected technology
skyeye · 0 through 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
dromara
Description’s affected range: through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById. Vendor/CNA’s CVSS 4.0 assessment (base score 9.1/10) rates confidentiality and integrity impact as high; availability impact as none.
- CWE
- CWE-918
- CCR priority
- 29.6 /100 (P4)
- CVSS 3.1
- 7.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N · GitHub Advisory Database
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 03:17:07.463462+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107781.html