criticalCVSS 9.8Vulnerability

CVE-2026-52778

### Summary An unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This implementation is inherently flawed: it is vulnerable to Regular Expression Denial of Service (ReDoS / Stack Overflow) which can crash the server, and it creates a high-risk architecture where any logic bypass directly results in arbitrary PHP code execution. ### Details Affected Component - **File**: tools/bazar/fields/CalcField.php - **Method**: formatValuesBeforeSave($entry) - **Vulnerable Mechanism:** Combination of a complex recursive regex validation followed by eval(). The code attempts to implement a sandbox for mathematical operations by verifying the formula structure before executing it: ``` $regexpToCheckIfMathFormula = '/^((' . $number . '|' . $functions . '\s*\((?1)+\)|\((?1)+\))(?:' . $operators . '(?1))?)+$/'; if (preg_match($regexpToCheckIfMathFormula, $formula)) { $formula = preg_replace('!pi|π!', 'pi()', $formula); try { eval("\$value = $formula;"); // VULNERABLE LINE // ... ``` ### Architectural Flaws **PCRE Stack Overflow & ReDoS (The Immediate Exploit):** The regex definition heavily relies on a recursive pattern (?1)+. In PHP's PCRE engine, deeply nested recursive patterns are processed on the system stack. If an attacker inputs a formula with thousands of nested parentheses or repeating groups, the engine will either trigger a pcre.recursion_limit exhaust (returning false or null) or cause a Segmentation Fault, instantly crashing the PHP process (Denial of Service). **The "Validation-Before-Substitution" Trap:** The regex checks the $formula variable after it has tokenized and reassembled the input string. If any underlying function called during tokenization (like testEntryValue or future updates to getEntryValue) returns or leaks an

Properties

severity
critical
summary
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
epss_score
0.00561
cvss_score
9.8
ghsa_published
2026-07-09T21:03:04Z
source_url
https://github.com/advisories/GHSA-px5m-h76g-p7p8
ghsa_updated
2026-07-09T21:03:04Z
ghsa_id
GHSA-px5m-h76g-p7p8
cve_id
CVE-2026-52778
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
epss_percentile
0.44159

Related Entities (6)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]composer/yeswiki/yeswiki

AFFECTS (1)

[Software]composer/yeswiki/yeswiki

HAS_WEAKNESS (2)

[Weakness]Inefficient Regular Expression Complexity
[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-52778 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal