SiYuan WebSocket Vulnerability: Unfiltered Edits Exposure Risk
- Severity
- HIGH
- Affected component
- siyuan (go)
- Affected versions
- <= 0.0.0-20260313024916-fd6526133bb3
- Patched version
- v3.7.4
SiYuan versions before v3.7.4 reportedly contain a vulnerability that allows anonymous readers to receive unfiltered edits including protected documents.
What happened
An early warning has been issued regarding a vulnerability in SiYuan versions before v3.7.4. This vulnerability, tracked as GHSA-MW8R-MW84-88V2 and GHSA-Q6G5-M978-C6V9, involves a publish-boundary bypass in WebSocket broadcast sessions. It appears to allow anonymous readers to receive a live, unfiltered feed of all edits, including those to password-protected and forbidden documents, without requiring authentication. The vulnerability has not been exploited in the wild according to current reports.
The affected component is siyuan (go) with versions <= 0.0.0-20260313024916-fd6526133bb3. The vulnerability is under investigation and the recommended action is to upgrade to SiYuan v3.7.4 or later to mitigate the risk.
What to do about it
- Upgrade SiYuan to version v3.7.4 or later to address the vulnerability.
- Review your SiYuan deployment to ensure it is running a patched version.
- Monitor the primary sources for updates on the vulnerability and any additional mitigations that may be recommended.
How 0Day would have caught this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if you are using SiYuan versions before v3.7.4.
What should I do right now?
Upgrade to SiYuan v3.7.4 or later as soon as possible.
Has this been exploited in the wild?
There are no reports of this vulnerability being exploited in the wild at this time.