Unauthenticated WebSocket Vulnerability in SiYuan Knowledge Management System
CVE-2026-33203
7.5HIGH
What is CVE-2026-33203?
The SiYuan knowledge management system possesses a vulnerability in its WebSocket server, which allows unauthenticated connections due to a specific query parameter. This flaw enables remote attackers to send malformed JSON messages that, when processed, can lead to runtime errors and crashes, resulting in a denial of service. This issue is addressed in version 3.6.2, making an upgrade essential for maintaining system integrity.
Affected Version(s)
siyuan < 3.6.2
