CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.7.4 are vulnerable to a publish-boundary bypass in WebSocket broadcast sessions, enabling unauthorized access to sensitive content. This flaw allows attackers to establish a WebSocket connection and receive real-time updates, including password-protected and restricted documents, without needing authentication. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.