CVE-2026-73054Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream including document identifiers, titles, and operation logs.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-15); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-15: 2Mentions · 2026-08-16: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 108-1508-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-152
Disclosure2
2026-08-161
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-73054 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between auth… https://www.cve.org/CVERecord?id=CVE-2026-73054

    Post summary

    A new authentication bypass in SiYuan WebSocket handling has been disclosed, affecting all versions prior to 3.7.4.

    000301.6K
    58.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73054 SiYuan v3.7.4 Authentication Bypass via WebSocket Query Parameter Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73054

    Post summary

    The brief text announces CVE-2026-73054 as an authentication bypass in SiYuan v3.7.4 via WebSocket query parameters, without providing any PoC, exploit, mitigation, or evidence of active exploitation.

    00000109
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-73054 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between auth… https://www.cve.org/CVERecord?id=CVE-2026-73054 ----- Traducción: CVE-2026-73054 Las… https://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-73054, detailing an authentication bypass in SiYuan’s WebSocket endpoint, but does not provide evidence of exploitation, a PoC, or a patch.

    0000027
    98 followersView on X

Explore more