CVE-2026-73054: SiYuan before v3.7.4 Authentication Bypass via WebSocket
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream including document identifiers, titles, and operation logs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4 - Compensating control
Until SiYuan is upgraded to 3.7.4 or later, restrict network access to the WebSocket endpoint so unauthenticated clients cannot reach it (e.g., via firewall/ACL/WAF rules).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73054?
The severity of CVE-2026-73054 is rated as high with a score of 7.5.
How do I fix CVE-2026-73054?
To fix CVE-2026-73054, upgrade SiYuan to version 3.7.4 or later.
What systems are affected by CVE-2026-73054?
CVE-2026-73054 affects SiYuan versions prior to 3.7.4.
What type of vulnerability is CVE-2026-73054?
CVE-2026-73054 is an authentication bypass vulnerability via the WebSocket endpoint.
Can CVE-2026-73054 be exploited remotely?
Yes, CVE-2026-73054 can be exploited remotely by unauthenticated attackers.