SiYuan has a security flaw
The flaw affects SiYuan before v3.7.4 and has a security flaw.
- Severity
- HighCVSS 3.1 · 8.6
- Fix
- Fixed in 0.0.0-20260725123945-77421530be4aFix recorded on Aug 26, 2026
- Affected versions
- before 0.0.0-20260725123945-77421530be4a
- Weakness
- CWE-522Insufficiently Protected Credentials
- Exploit likelihood
- 0.25% in 30 daysEPSS, higher than 16% of known flaws
- Affects
- SiYuan
How it works
siyuan has a security flaw siyuan versions older than v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode.
What to do
Check whether the installed SiYuan version is older than v3.7.4.
Update SiYuan to v3.7.4 or newer. Then verify the installed version.
Technical details
The source identifies SiYuan as the affected product. Affected ranges: before v3.7.4. Fixed versions: v3.7.4.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact None No data tampering
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Open in FIRST.org calculatorReferences
- github.com · GHSA-34fj-mwm6-fjfg vendor advisory
- nvd.nist.gov · CVE-2026-72794 vdb entry
- vulncheck.com · siyuan-before-session-cookie-key-disclosure-via-getconf NVD GitHub Advisory
- github.com · commit 7742153 GitHub Advisory