PT-2026-71236 · Siyuan · Siyuan
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
siyuan versions prior to 3.7.4
Description
In publish mode, the
/api/system/getConf endpoint exposes the CookieKey variable, which is the cryptographic key used to sign session cookies, to unauthenticated users or those with RoleReader permissions. This occurs because the masking process for this endpoint fails to remove the secret key, unlike the configuration-export endpoint. An attacker can retrieve this key to forge or modify session cookies that the server accepts as authentic. Depending on the server configuration, such as when no access-auth code is set, this can lead to user impersonation or unauthorized administrative access.Recommendations
Update siyuan to version 3.7.4 or later.
As a temporary mitigation, restrict access to the
/api/system/getConf endpoint.Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan