CVE-2026-72793: SiYuan: getConf leaks session key, enables admin takeover

GHSA-h4v5-crx2-3cv4 HIGH PoC AVAILABLE CISA: TRACK*
Published August 12, 2026
CISO Take

SiYuan, a self-hosted note-taking and knowledge management tool, ships an unauthenticated /api/system/getConf endpoint that leaks the session-cookie signing key, the host OS username, and the encryption key material protecting notebooks — before v3.7.4. Because the vulnerability requires no authentication and no user interaction (CVSS 8.6, AV:N/AC:L/PR:N/UI:N), any attacker who can reach the endpoint can forge session cookies to impersonate legitimate users, and on instances left without an access-auth code, escalate straight to administrator. Exploitation intelligence is currently muted — it's not in CISA KEV, no public exploit or Nuclei template exists, and CISA's SSVC rates it TRACK_STAR (lowest-priority track) with an EPSS score of just 0.24%, though that still places it in the top 84th percentile of scored CVEs by exploitation likelihood. For teams that run SiYuan as a personal or team knowledge base feeding AI workflows, the leaked notebook encryption keys are the sharper risk since they threaten confidentiality of whatever content is stored there. Patch to v3.7.4 or later immediately, set a mandatory access-auth code on every instance, restrict network exposure to trusted networks/VPN, and rotate signing keys post-upgrade since any previously exposed key material should be treated as compromised.

Sources: NVD GitHub Advisory EPSS CISA KEV VulnCheck ATLAS

What is the risk?

Exploitability is high — the endpoint requires no authentication, no privileges, and no user interaction, and a single unauthenticated HTTP request is enough to extract the leaked secrets (CVSS 8.6, scope-changed confidentiality-only impact: C:H/I:N/A:N). The realistic blast radius is amplified beyond a simple info-leak because the leaked session-signing key enables cookie forgery/impersonation, and instances without an access-auth code configured can be escalated directly to administrator. Countering that, near-term mass-exploitation signals are low: EPSS sits at 0.24% (top 84th percentile, not top-tier), the CVE is absent from CISA KEV, no public exploit code or Nuclei template has surfaced, and CISA's SSVC decision is TRACK_STAR — the lowest-urgency track. Net assessment: high technical severity with currently low observed/predicted exploitation activity, but the low bar to exploit (one unauthenticated GET) means this could shift quickly once a PoC circulates.

How does the attack unfold?

Reconnaissance
Attacker identifies an internet-exposed SiYuan instance and sends an unauthenticated GET request to /api/system/getConf.
AML.T0006
Key Exposure
The response leaks the session-cookie signing key, OS username, and encrypted-notebook key material without masking.
AML.T0055
Session Forgery / Escalation
Attacker forges a valid session cookie to impersonate a user, or gains outright admin access if no access-auth code is configured.
AML.T0091
Impact
Attacker exfiltrates notebook content or fully controls the instance as administrator, including any connected AI plugin configurations.
AML.T0025

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260725132049-2d8b98395a91 0.0.0-20260725132049-2d8b98395a91
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →
siyuan — — No patch

How severe is it?

CVSS 3.1
8.6 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 33% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C High
I None
A None

What should I do?

1 step
  1. Upgrade to SiYuan v3.7.4 or later, which masks sensitive fields in the /api/system/getConf response. Until patched, do not expose SiYuan directly to untrusted networks — bind it to localhost or a VPN, and place any remote access behind an authenticating reverse proxy. Set a non-default access-auth code on every instance; this is the deployment's only real defense against outright admin takeover pre-patch. After upgrading, rotate session-signing keys and treat any previously exposed encrypted-notebook key material as compromised — re-encrypt or re-key affected notebooks. Monitor access logs for anonymous or unusual requests to /api/system/getConf as a detection signal for attempted exploitation.

What does CISA's SSVC say?

Decision Track*
Exploitation poc
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.6.2 - Data for AI systems
NIST AI RMF
GOVERN 1.5 - Cybersecurity risk management integrated with AI risk management
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72793?

SiYuan, a self-hosted note-taking and knowledge management tool, ships an unauthenticated /api/system/getConf endpoint that leaks the session-cookie signing key, the host OS username, and the encryption key material protecting notebooks — before v3.7.4. Because the vulnerability requires no authentication and no user interaction (CVSS 8.6, AV:N/AC:L/PR:N/UI:N), any attacker who can reach the endpoint can forge session cookies to impersonate legitimate users, and on instances left without an access-auth code, escalate straight to administrator. Exploitation intelligence is currently muted — it's not in CISA KEV, no public exploit or Nuclei template exists, and CISA's SSVC rates it TRACK_STAR (lowest-priority track) with an EPSS score of just 0.24%, though that still places it in the top 84th percentile of scored CVEs by exploitation likelihood. For teams that run SiYuan as a personal or team knowledge base feeding AI workflows, the leaked notebook encryption keys are the sharper risk since they threaten confidentiality of whatever content is stored there. Patch to v3.7.4 or later immediately, set a mandatory access-auth code on every instance, restrict network exposure to trusted networks/VPN, and rotate signing keys post-upgrade since any previously exposed key material should be treated as compromised.

Is CVE-2026-72793 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72793, increasing the risk of exploitation.

How to fix CVE-2026-72793?

Upgrade to SiYuan v3.7.4 or later, which masks sensitive fields in the /api/system/getConf response. Until patched, do not expose SiYuan directly to untrusted networks — bind it to localhost or a VPN, and place any remote access behind an authenticating reverse proxy. Set a non-default access-auth code on every instance; this is the deployment's only real defense against outright admin takeover pre-patch. After upgrading, rotate session-signing keys and treat any previously exposed encrypted-notebook key material as compromised — re-encrypt or re-key affected notebooks. Monitor access logs for anonymous or unusual requests to /api/system/getConf as a detection signal for attempted exploitation.

What systems are affected by CVE-2026-72793?

This vulnerability affects the following AI/ML architecture patterns: Self-hosted knowledge management / notebook platforms, Personal/team knowledge bases feeding RAG pipelines, Plugin ecosystems with AI integrations.

What is the CVSS score for CVE-2026-72793?

CVE-2026-72793 has a CVSS v3.1 base score of 8.6 (HIGH). The EPSS exploitation probability is 0.41%.

What is the AI security impact?

Affected AI Architectures

Self-hosted knowledge management / notebook platformsPersonal/team knowledge bases feeding RAG pipelinesPlugin ecosystems with AI integrations

MITRE ATLAS Techniques

AML.T0025 Exfiltration via Cyber Means
AML.T0055 Unsecured Credentials

Compliance Controls Affected

ISO 42001: A.6.2
NIST AI RMF: GOVERN 1.5
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.

Exploitation Scenario

An attacker scans for internet-reachable SiYuan instances and issues a single unauthenticated GET to /api/system/getConf. The response hands back the session-cookie signing key, the host's OS username (via the pandoc path), and the key material protecting encrypted notebooks — all unmasked. Using the signing key, the attacker crafts a forged, validly-signed session cookie for an arbitrary user; if the instance has no access-auth code configured, they mint themselves an administrator session outright. From there they read and exfiltrate the victim's notebooks — potentially including research notes or knowledge-base content used to feed AI workflows — or use admin access to install a malicious plugin for persistence.

Weaknesses (CWE)

CWE-522 — Insufficiently Protected Credentials: The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

  • [Architecture and Design] Use an appropriate security mechanism to protect the credentials.
  • [Architecture and Design] Make appropriate use of cryptography to protect the credentials.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 4, 2026
First Seen
August 13, 2026

Related Vulnerabilities