What is CVE-2026-72810?
SiYuan versions before v3.7.4 have a publish-boundary bypass vulnerability in WebSocket broadcast sessions. This allows anonymous readers to passively receive unfiltered real-time edit events. Affected systems should be upgraded to v3.7.4 or later.
Azərbaycanca: SiYuan proqramında (v3.7.4-dən əvvəlki versiyalar) WebSocket vasitəsilə "publish-boundary" qorunmasını keçən boşluq aşkarlanıb. Bu zəiflik anonim oxuculara filtrlənməmiş redaktələri real vaxtda əldə etməyə imkan verir. Təsirlənən sistemləri v3.7.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: SiYuan
FAQ1
What is the security issue in SiYuan related to WebSocket broadcasting?
SiYuan versions before v3.7.4 have a publish-boundary bypass vulnerability in WebSocket broadcast sessions, allowing anonymous readers to passively receive unfiltered real-time edit events.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.