High severity8.6NVD Advisory· Published Aug 14, 2026· Updated Aug 26, 2026
CVE-2026-72810
CVE-2026-72810
Description
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/siyuan-note/siyuan/kernelGo | < 0.0.0-20260723013612-ba948639d7f6 | 0.0.0-20260723013612-ba948639d7f6 |
Affected products
2- ghsa-coordsRange: < 0.0.0-20260723013612-ba948639d7f6
- Range: <v3.7.4
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-mw8r-mw84-88v2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-72810ghsaADVISORY
- github.com/siyuan-note/siyuan/commit/ba948639d7f6bd5594ce584072dc68310da87a68ghsaWEB
- github.com/siyuan-note/siyuan/security/advisories/GHSA-mw8r-mw84-88v2nvdWEB
- www.vulncheck.com/advisories/siyuan-before-publish-boundary-bypass-via-websocketnvdWEB
News mentions
1- Siyuan Note: 25 Vulnerabilities Including RCE and Auth Bypass Disclosed TogetherVypr Intelligence · Aug 15, 2026