Security Advisory

CVE-2026-72810

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-14 11:35:24
Last updated 2026-08-18 02:26:57
Assigner VulnCheck
CVSS score 9.2
State PUBLISHED

Description

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.