PT-2026-73058 · Siyuan · Siyuan
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
An authentication bypass exists in the WebSocket endpoint due to differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can use a malicious WebSocket URI containing duplicated query parameters to bypass access auth code validation. This allows the attacker to receive the live kernel event stream, which includes document identifiers, titles, and operation logs.
Recommendations
Update SiYuan to version 3.7.4 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan