What is CVE-2026-73054?
SiYuan note-taking application versions before 3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint. The issue arises from differential parsing of query parameters between authentication exemption and session quarantine checks, allowing unauthenticated attackers to gain access via a crafted WebSocket URI with duplicated query elements. Affected users should immediately upgrade to SiYuan version 3.7.4 or later.
Azərbaycanca: SiYuan qeyd dəftəri tətbiqinin 3.7.4 versiyasından əvvəlki versiyalarında WebSocket üçün təsdiqləmə bypass zəifliyi mövcuddur. Bu, sorğu parametrlərinin təsdiqləmə istisnası ilə sessiya karantin yoxlamaları arasında fərqli parse edilməsi səbəbindən baş verir ki, bu da autentifikasiyasız hücumçulara təkrarlanan sorğu elementi ilə zərərli WebSocket URI-si vasitəsilə giriş əldə etməyə imkan verir. Təsirlənən istifadəçilər dərhal SiYuan'u ən azı 3.7.4 versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the SiYuan application are affected by CVE-2026-73054?
All versions of the SiYuan note-taking application prior to version 3.7.4 are affected.
What should users do to protect against CVE-2026-73054?
Users should immediately upgrade the SiYuan application to version 3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.