CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-107781: skyeye affected git revisions

CVE-2026-107781. CVSS 3.1 base score 7.4 (GitHub Advisory Database).

Affected technology

skyeye · 0 through 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
dromara

Description’s affected range: through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById. Vendor/CNA’s CVSS 4.0 assessment (base score 9.1/10) rates confidentiality and integrity impact as high; availability impact as none.

Published

CWE
CWE-918
CCR priority
29.6 /100 (P4)
CVSS 3.1
7.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N · GitHub Advisory Database
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107781.html