Session Cookie Signing Key Disclosure in Siyuan by Siyuan Note
CVE-2026-72794
9.2CRITICAL
What is CVE-2026-72794?
Versions of Siyuan prior to v3.7.4 contain a vulnerability that allows unauthorized users to access the session cookie signing key via the /api/system/getConf endpoint. When the application is in publish mode, attackers can exploit this exposure to retrieve the CookieKey value, enabling them to forge valid session cookies. This vulnerability could lead to user impersonation or unauthorized administrative access, jeopardizing the security of the affected systems.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
