CVE-2026-74802

SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can craft malicious webpages that establish WebSocket connections to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to attacker-chosen targets, enabling authenticated network pivoting through the victim's machine.

Scoring

Severity
HIGH
CVSS base score
8.2
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS probability
0.12%
CWE
CWE-346
Published
2026-08-17
Last modified
2026-08-28

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs