Description
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.
Published: 2026-08-14
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan note versions before 3.7.4 contain a publish‑boundary bypass in the WebSocket broadcast sessions. An unauthenticated client can open a WebSocket connection to the publish surface and receive unfiltered edit events, including those for password‑protected or otherwise forbidden documents. The missing authorization check – a form of weakness enumerated as CWE‑862 – allows attackers to read any content that passes through the WebSocket stream. This results in a direct loss of confidentiality for all documents served by the instance.

Affected Systems

The vulnerability affects the SiYuan Note product, specifically all releases prior to v3.7.4. Any instance running those versions with the publish service enabled is susceptible unless the publish functionality has been disabled or otherwise protected by network controls.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical risk. EPSS is not available and the issue is not listed in the CISA KEV catalog, but the lack of an authentication gate on the WebSocket endpoint makes exploitation straightforward for any network actor who can reach the publish surface. An attacker simply establishes a WebSocket connection and passively receives real‑time content events, leading to comprehensive data exfiltration without any additional credentials or system compromise.

Generated by OpenCVE AI on August 14, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to SiYuan v3.7.4 or newer, which removes the publish‑boundary bypass.
  • If upgrading is delayed, disable external access to the publish WebSocket endpoint or limit it to trusted hosts only, ensuring that untrusted clients cannot connect.
  • Configure a firewall or reverse proxy to block or restrict WebSocket traffic to the publish surface, mitigating the risk of unauthorized data exposure.

Generated by OpenCVE AI on August 14, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Fri, 14 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.
Title SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T11:35:24.086Z

Reserved: 2026-08-10T15:11:49.794Z

Link: CVE-2026-72810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T12:16:43.760

Modified: 2026-08-14T12:16:43.760

Link: CVE-2026-72810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T13:45:16Z

Weaknesses