CVE-2026-73054
Received Received - Intake

SiYuan Authentication Bypass via WebSocket Parameter Duplication

Vulnerability report for CVE-2026-73054, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulnCheck

Description

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream including document identifiers, titles, and operation logs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan versions before v3.7.4 have an authentication bypass flaw in the WebSocket endpoint. The issue arises from inconsistent parsing of query parameters between authentication exemption and session quarantine checks. Attackers can exploit this by crafting a malicious WebSocket URI with duplicated query parameters to bypass access authentication and gain access to the live kernel event stream.

Detection Guidance

Check SiYuan logs for unusual WebSocket connections or requests with duplicated query parameters. Monitor network traffic for unauthenticated WebSocket handshakes to the vulnerable endpoint.

Impact Analysis

Unauthenticated attackers could access sensitive data like document identifiers, titles, and operation logs through the live kernel event stream. This could lead to unauthorized data exposure or further exploitation of the system.

Compliance Impact

This vulnerability could result in unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations using affected SiYuan versions may face compliance violations, potential fines, and reputational damage due to data breaches.

Mitigation Strategies

Upgrade SiYuan to version v3.7.4 or later to patch the authentication bypass. If immediate upgrade is not possible, restrict WebSocket access via firewall rules or disable WebSocket endpoints until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73054. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart