Executive brief
YMFE YApi, a popular platform for managing and testing APIs, contains a security vulnerability that could allow attackers to run malicious scripts in a user's browser. If an attacker successfully exploits this flaw, they could potentially steal sensitive user data or gain unauthorized access to the platform. This impacts organizations using YApi to document and share internal API specifications.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in YMFE YApi version 1.12.0. The issue stems from improper neutralization of user-supplied input during the generation of web pages, allowing an attacker to inject malicious scripts. The attack vector is network-based and requires user interaction (UI:R), typically involving a victim visiting a specially crafted link or viewing malicious content within the YApi interface. Successful exploitation can lead to the execution of arbitrary JavaScript in the context of the victim's session, potentially resulting in session hijacking or unauthorized data exfiltration. At the time of reporting, the vulnerability is identified in version 1.12.0.
Affected products
- YMFE yapi 1.12.0
Timeline
- 2026-03-09: disclosed: Initial disclosure and CVE assignment
- 2026-03-09: advisory: NVD publication date