YApi Unauthorized Creation User And Mock RCE

Yapi is not authorized to create an account and can create a task in the background. Any command can be specified by the command parameter

FOFA query rule: app="YAPI"

Demo

img