What is CVE-2026-74799?
SiYuan versions before 3.7.4 register Go net/http/pprof debug endpoints without authentication when the "--mode" flag is not set to exactly "prod". This vulnerability allows attackers to extract in-memory secrets, including AccessAuthCode and AI provider API keys, via heap dumps. Users should update to version 3.7.4 or later, or ensure debug endpoints are properly secured and authenticated.
Azərbaycanca: SiYuan proqramının 3.7.4-dən əvvəlki versiyalarında, "--mode" parametri dəqiq "prod" olaraq təyin edilmədikdə, debug endpoint-ləri autentifikasiya olmadan qeydiyyatdan keçir. Bu zəiflik təcavüzkarlara heap dump vasitəsilə AccessAuthCode və AI təminatçı API açarları kimi həssas yaddaşdaxili məlumatları əldə etməyə imkan verir. İstifadəçilər proqramı ən geci 3.7.4 versiyasına yeniləməli və ya debug rejimini deaktiv edərək autentifikasiyanı təmin etməlidirlər.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of SiYuan are affected by CVE-2026-74799?
This vulnerability affects SiYuan versions before 3.7.4.
What kind of sensitive data can attackers extract through this vulnerability?
Attackers can extract in-memory secrets such as AccessAuthCode and AI provider API keys via heap dumps.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.