Cross-Site WebSocket Hijacking in SiYuan by SiYuanNote
CVE-2026-74802

8.2NONE

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-74802?

SiYuan versions prior to 3.7.4 are vulnerable to a cross-site WebSocket hijacking attack. This vulnerability exists in the admin-only /ws/network/proxy endpoint, where origin validation is improperly handled. By setting CheckOrigin to always return true, an attacker can craft malicious web pages that initiate WebSocket connections to this endpoint. This allows the attacker to manipulate the SiYuan kernel process to proxy arbitrary network traffic to selected targets, permitting unauthorized network access through the victim's device.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.