Authentication Bypass Vulnerability in SiYuan by SiYuan Developer
CVE-2026-72809
7.1HIGH
What is CVE-2026-72809?
SiYuan versions prior to 3.7.4 contain a vulnerability that allows unauthorized administrative access through specific endpoints, including /api/system/exit and /assets/*. This occurs due to the CheckAuth function improperly handling requests made from the loopback address (127.0.0.1), which bypasses access controls even when an authentication token is configured. Furthermore, when utilizing a fixed-port reverse proxy, requests can be forwarded to the kernel without proper authentication, potentially allowing a remote attacker to exploit this flaw for unauthorized admin privileges.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
