CVE-2026-72810: SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72810?
CVE-2026-72810 has a high severity score of 8.6.
How do I fix CVE-2026-72810?
To fix CVE-2026-72810, update SiYuan to version 3.7.4 or later.
What type of vulnerability is CVE-2026-72810?
CVE-2026-72810 is a publish-boundary bypass vulnerability in WebSocket broadcast sessions.
Who is affected by CVE-2026-72810?
CVE-2026-72810 affects users of SiYuan versions prior to 3.7.4.
What impact does CVE-2026-72810 have on security?
CVE-2026-72810 allows anonymous readers to receive unfiltered edits, posing a risk of content exposure.