Impact
SiYuan versions prior to 3.7.4 allow unauthenticated attackers to bypass authentication by sending a specially crafted WebSocket URI containing duplicate query parameters. The server’s parsing logic treats the exemption and session quarantine checks inconsistently, enabling the attacker to acquire the live kernel event stream that includes document identifiers, titles, and operation logs. This grants the attacker unauthorized access to potentially sensitive data without authenticating.
Affected Systems
The vulnerability affects all installations of SiYuan, specifically versions earlier than 3.7.4, as distributed by the vendor siyuan-note. No other products or versions are presently listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. Attackers can exploit the flaw remotely if the WebSocket endpoint is reachable from the internet or an internal network, thereby compromising confidentiality of confidential documents and logs. The impact is limited to unauthorized information disclosure rather than remote code execution.
OpenCVE Enrichment