CVE-2026-73054

7.5

SiYuan · SiYuan

SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability involving the websocket implementation, allowing unauthenticated remote access.

Executive summary

A high-severity authentication bypass vulnerability in SiYuan allows unauthenticated remote attackers to gain unauthorized access to the application via websocket communication.

Vulnerability

The application suffers from improper authentication (CWE-287), specifically within its websocket handling, which permits unauthenticated attackers to interact with the system without valid credentials.

Business impact

With a CVSS score of 7.5, this vulnerability represents a critical failure in the application security model. Exploitation provides attackers with unauthorized access to system functions, creating a high risk of data exfiltration and administrative compromise.

Remediation

Immediate Action: Upgrade the SiYuan installation to version 3.7.4 or later to resolve the websocket authentication bypass.

Proactive Monitoring: Review websocket traffic and connection logs for unusual patterns or connections originating from unauthorized or external sources.

Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect and filter incoming websocket traffic for suspicious handshake patterns or unauthorized access attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this authentication bypass requires immediate attention. Security teams must ensure all instances of SiYuan are patched to version 3.7.4 to prevent potential unauthorized access and maintain the integrity of the application.

More SiYuan CVEs