CVE-2026-107781 | Dromara Skyeye OnlyOffice save callback editUploadOfficeFileById url/key server-side request forgery

SecurityVulns

A vulnerability classified as critical was found in Dromara Skyeye. Affected is the function editUploadOfficeFileById of the component OnlyOffice save callback. The manipulation of the argument url/key results in server-side request forgery.

This vulnerability is known as CVE-2026-107781. It is possible to launch the attack remotely. No exploit is available.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More