CVE-2026-72801: SiYuan before v3.7.4 Information Disclosure via Encryption Key Material
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4 - Compensating control
Disable or restrict unauthenticated access to the publish-mode endpoints that disclose encrypted-notebook key-derivation material and wrapped data keys, until SiYuan is upgraded to v3.7.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72801?
CVE-2026-72801 has a high severity rating of 7.5.
What is the risk associated with CVE-2026-72801?
The risk level for CVE-2026-72801 is categorized as 43.
How do I fix CVE-2026-72801?
To fix CVE-2026-72801, upgrade to SiYuan version 3.7.4 or later.
What does CVE-2026-72801 affect?
CVE-2026-72801 affects versions of SiYuan prior to 3.7.4 by disclosing key-derivation material.
What kind of data is disclosed in CVE-2026-72801?
CVE-2026-72801 discloses encrypted-notebook key-derivation material, including Argon2id salt and password verifiers.