Authentication Bypass Vulnerability in SiYuan by SiYuan Technology
CVE-2026-73054
8.7HIGH
What is CVE-2026-73054?
Versions of SiYuan prior to v3.7.4 are vulnerable to an authentication bypass issue within the WebSocket endpoint. This vulnerability is due to differential parsing of query parameters, which allows unauthenticated attackers to create malicious WebSocket URIs containing duplicated query parameters. This bypasses critical access authentication checks, enabling attackers to receive the live kernel event stream, which exposes sensitive information such as document identifiers, titles, and operation logs.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
