WebSocket Broadcast Vulnerability in SiYuan by SiYuan
CVE-2026-72810

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-72810?

A vulnerability in earlier versions of SiYuan allows attackers to exploit WebSocket broadcast sessions. This flaw enables anonymous users to receive unfiltered edits in real time, including access to sensitive documents that should be password-protected or forbidden. By establishing a WebSocket connection to the publish surface, attackers can bypass authentication mechanisms, potentially leading to unauthorized exposure of confidential information.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.