CVE-2026-107781 | Dromara Skyeye OnlyOffice save callback editUploadOfficeFileById url/key server-side request forgery
A vulnerability classified as critical was found in Dromara Skyeye. Affected is the function editUploadOfficeFileById of the component OnlyOffice save callback. The manipulation of the argument url/key results in server-side request forgery.
This vulnerability is known as CVE-2026-107781. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More