PT-2026-73143 · Siyuan · Siyuan
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan kernel versions prior to 3.7.4
Description
An improper restriction of excessive authentication attempts exists in the
CheckAuth() middleware. The middleware accepts the Conf.Api.Token API token through an Authorization header (Token/Bearer) or a token query parameter. Neither of these paths is protected by the application's CAPTCHA or lockout mechanisms, specifically NeedCaptcha and WrongAuthCount. This allows an unauthenticated remote attacker to perform unlimited automated guesses of the API token. If a short or weak custom token is used, a successful guess grants full RoleAdministrator access, allowing for arbitrary SQL queries and file operations.Recommendations
Update SiYuan kernel to version 3.7.4 or later.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan