GO · AUGUST 2026 · EARLY WARNING

SiYuan WebSocket Vulnerability: Unfiltered Edits Exposure Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
siyuan (go)
Affected versions
<= 0.0.0-20260313024916-fd6526133bb3
Patched version
v3.7.4
GHSA-MW8R-MW84-88V2GHSA-Q6G5-M978-C6V9

SiYuan versions before v3.7.4 reportedly contain a vulnerability that allows anonymous readers to receive unfiltered edits including protected documents.

What happened

An early warning has been issued regarding a vulnerability in SiYuan versions before v3.7.4. This vulnerability, tracked as GHSA-MW8R-MW84-88V2 and GHSA-Q6G5-M978-C6V9, involves a publish-boundary bypass in WebSocket broadcast sessions. It appears to allow anonymous readers to receive a live, unfiltered feed of all edits, including those to password-protected and forbidden documents, without requiring authentication. The vulnerability has not been exploited in the wild according to current reports.

The affected component is siyuan (go) with versions <= 0.0.0-20260313024916-fd6526133bb3. The vulnerability is under investigation and the recommended action is to upgrade to SiYuan v3.7.4 or later to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if you are using SiYuan versions before v3.7.4.

What should I do right now?

Upgrade to SiYuan v3.7.4 or later as soon as possible.

Has this been exploited in the wild?

There are no reports of this vulnerability being exploited in the wild at this time.

Sources

Join the 0Day waitlist →

← Back to all threats