Description
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream including document identifiers, titles, and operation logs.
Published: 2026-08-15
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan versions prior to 3.7.4 allow unauthenticated attackers to bypass authentication by sending a specially crafted WebSocket URI containing duplicate query parameters. The server’s parsing logic treats the exemption and session quarantine checks inconsistently, enabling the attacker to acquire the live kernel event stream that includes document identifiers, titles, and operation logs. This grants the attacker unauthorized access to potentially sensitive data without authenticating.

Affected Systems

The vulnerability affects all installations of SiYuan, specifically versions earlier than 3.7.4, as distributed by the vendor siyuan-note. No other products or versions are presently listed as affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. Attackers can exploit the flaw remotely if the WebSocket endpoint is reachable from the internet or an internal network, thereby compromising confidentiality of confidential documents and logs. The impact is limited to unauthorized information disclosure rather than remote code execution.

Generated by OpenCVE AI on August 15, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.7.4 or later to apply the vendor patch that corrects the WebSocket query parameter validation.
  • If upgrading immediately is infeasible, disable the WebSocket endpoint in the SiYuan configuration or block it using firewall rules to prevent unauthenticated access.
  • Apply network segmentation so that the WebSocket endpoint is not exposed to untrusted networks and whitelist only trusted IP addresses if the endpoint must remain online.

Generated by OpenCVE AI on August 15, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream including document identifiers, titles, and operation logs.
Title SiYuan before v3.7.4 Authentication Bypass via WebSocket
First Time appeared B3log
B3log siyuan
Weaknesses CWE-287
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-15T21:44:53.915Z

Reserved: 2026-08-10T19:10:18.101Z

Link: CVE-2026-73054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T22:16:55.290

Modified: 2026-08-15T22:16:55.290

Link: CVE-2026-73054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T23:30:16Z

Weaknesses