GHSA-x8p6-569w-fmmrLow· 8.2▾ SunlitDuplicate Advisory: SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-3cc2-h3v6-rqpq. This link is maintained to preserve external references.
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can craft malicious webpages that establish WebSocket connections to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to attacker-chosen targets, enabling authenticated network pivoting through the victim's machine.
github.com/siyuan-note/siyuan/kernel < 0.0.0-20260803045322-cb67e0b4fab5Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-74802LowSiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
CVE-2026-54069CriticalSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
GHSA-69jp-f2p8-9vrgHigh· 7.5Duplicate Advisory: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
CVE-2026-74904High· 7.5SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
GHSA-p23f-cm6q-2qp8Medium· 5.7SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
GHSA-x8gv-g2g3-65fjHigh· 8.2SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)