Authentication Bypass Vulnerability in SiYuan by SiYuan Technology
CVE-2026-73054

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-73054?

Versions of SiYuan prior to v3.7.4 are vulnerable to an authentication bypass issue within the WebSocket endpoint. This vulnerability is due to differential parsing of query parameters, which allows unauthenticated attackers to create malicious WebSocket URIs containing duplicated query parameters. This bypasses critical access authentication checks, enabling attackers to receive the live kernel event stream, which exposes sensitive information such as document identifiers, titles, and operation logs.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.