CVE-2026-72801: SiYuan: key material leak enables offline cracking

GHSA-8x84-r2ff-h8pq HIGH PoC AVAILABLE CISA: TRACK*
Published August 12, 2026
CISO Take

SiYuan, a self-hosted note-taking application some teams use as an encrypted personal knowledge base for LLM and RAG workflows, ships an unauthenticated endpoint in its publish mode that leaks the Argon2id salt, cost parameters, password verifier, and wrapped data key for encrypted notebooks. Because the attacker needs no credentials or user interaction (AV:N/PR:N/UI:N, CVSS 7.5) and can retrieve this material over the network, any internet-exposed publish-mode deployment hands adversaries everything required to brute-force the master password completely offline and without any rate limiting. Exploitation likelihood sits around the 84th EPSS percentile (0.24%) and CISA's SSVC decision is Track*, meaning it isn't flagged for emergency action but belongs on the patch backlog; there is no known KEV listing, public exploit, or Nuclei template yet. Impact is confidentiality-only (C:H/I:N/A:N), so notebook contents — which can include proprietary data feeding an AI knowledge base — are at risk of full offline decryption, not tampering or downtime. Patch to SiYuan v3.7.4+ immediately on any instance running publish mode, and until then take publish-mode endpoints off the public internet or front them with an authenticating reverse proxy.

Sources: NVD GitHub Advisory EPSS CISA SSVC

What is the risk?

Exploitability is high in relative terms: the attack requires no authentication, no user interaction, and low complexity (AC:L) — just network reachability to a publish-mode SiYuan instance. However, this isn't a single-step compromise; the attacker must then run a compute-intensive offline Argon2id cracking job, and success depends entirely on the strength of the target's master password. Impact is confined to confidentiality (C:H) with no integrity or availability effect, but for organizations using SiYuan as an encrypted knowledge repository — including as a backend for personal or team RAG/LLM workflows — a successful crack means full plaintext access to notebook contents. Exposure is currently limited: EPSS sits at 0.24% (84th percentile), the CVE is not in CISA KEV, and no public exploit or scanner template exists, so mass exploitation is unlikely near-term. Overall risk is best characterized as moderate-and-patch-now: low current exploitation pressure, but a straightforward, well-understood attack path (leaked KDF material → unrestricted offline brute-force) that only gets easier as cracking hardware improves.

How does the attack unfold?

Recon
Attacker identifies an internet-exposed SiYuan instance running in publish mode.
AML.T0006
Key material disclosure
Attacker queries the unauthenticated publish-mode endpoint to retrieve the Argon2id salt, cost parameters, password verifier, and wrapped notebook data key.
AML.T0055
Offline password cracking
Attacker runs unlimited offline Argon2id brute-force against the password verifier, unconstrained by any rate limiting or lockout.
Data decryption
Attacker uses the recovered master password to unwrap the data key and decrypt the notebook, gaining full read access to its contents, including any data feeding downstream AI/RAG workflows.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260724102025-3bc014c7dc32 0.0.0-20260724102025-3bc014c7dc32
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
7.5 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 33% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Moderate
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Unchanged
C High
I None
A None

What should I do?

1 step
  1. Upgrade to SiYuan v3.7.4 or later, which fixes the endpoint disclosure — this is the only complete remediation. Until patched, disable publish mode or restrict it to trusted networks/VPN rather than exposing it directly to the internet; if publish mode must remain internet-facing, front it with an authenticating reverse proxy (HTTP basic auth, OAuth proxy, etc.) so the vulnerable endpoint isn't reachable unauthenticated. Rotate the master password on any notebook that was exposed via an internet-facing publish-mode instance, since salt/verifier/wrapped-key material may already have been harvested. For detection, review web server or reverse-proxy logs for repeated unauthenticated requests to publish-mode key-material endpoints, and if SiYuan feeds an AI/RAG pipeline, audit that pipeline's access logs for unexpected bulk reads following any suspected key compromise.

What does CISA's SSVC say?

Decision Track*
Exploitation poc
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Data Leakage Auth Bypass RAG API AML.T0055

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
NIST AI RMF
MEASURE 2.7 - AI system security and resilience evaluated
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72801?

SiYuan, a self-hosted note-taking application some teams use as an encrypted personal knowledge base for LLM and RAG workflows, ships an unauthenticated endpoint in its publish mode that leaks the Argon2id salt, cost parameters, password verifier, and wrapped data key for encrypted notebooks. Because the attacker needs no credentials or user interaction (AV:N/PR:N/UI:N, CVSS 7.5) and can retrieve this material over the network, any internet-exposed publish-mode deployment hands adversaries everything required to brute-force the master password completely offline and without any rate limiting. Exploitation likelihood sits around the 84th EPSS percentile (0.24%) and CISA's SSVC decision is Track*, meaning it isn't flagged for emergency action but belongs on the patch backlog; there is no known KEV listing, public exploit, or Nuclei template yet. Impact is confidentiality-only (C:H/I:N/A:N), so notebook contents — which can include proprietary data feeding an AI knowledge base — are at risk of full offline decryption, not tampering or downtime. Patch to SiYuan v3.7.4+ immediately on any instance running publish mode, and until then take publish-mode endpoints off the public internet or front them with an authenticating reverse proxy.

Is CVE-2026-72801 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72801, increasing the risk of exploitation.

How to fix CVE-2026-72801?

Upgrade to SiYuan v3.7.4 or later, which fixes the endpoint disclosure — this is the only complete remediation. Until patched, disable publish mode or restrict it to trusted networks/VPN rather than exposing it directly to the internet; if publish mode must remain internet-facing, front it with an authenticating reverse proxy (HTTP basic auth, OAuth proxy, etc.) so the vulnerable endpoint isn't reachable unauthenticated. Rotate the master password on any notebook that was exposed via an internet-facing publish-mode instance, since salt/verifier/wrapped-key material may already have been harvested. For detection, review web server or reverse-proxy logs for repeated unauthenticated requests to publish-mode key-material endpoints, and if SiYuan feeds an AI/RAG pipeline, audit that pipeline's access logs for unexpected bulk reads following any suspected key compromise.

What systems are affected by CVE-2026-72801?

This vulnerability affects the following AI/ML architecture patterns: RAG pipelines.

What is the CVSS score for CVE-2026-72801?

CVE-2026-72801 has a CVSS v3.1 base score of 7.5 (HIGH). The EPSS exploitation probability is 0.41%.

What is the AI security impact?

Affected AI Architectures

RAG pipelines

MITRE ATLAS Techniques

AML.T0055 Unsecured Credentials

Compliance Controls Affected

EU AI Act: Article 15
NIST AI RMF: MEASURE 2.7
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.

Exploitation Scenario

An attacker scanning the internet for exposed SiYuan publish-mode instances (e.g., via fingerprinting the default publish UI) finds a target organization using SiYuan as a shared encrypted knowledge base, possibly one that also feeds a company RAG assistant. Without authenticating, the attacker hits the vulnerable endpoint and retrieves the Argon2id salt, cost parameters, password verifier, and wrapped data key for the target notebook. The attacker takes this material offline and runs a GPU-accelerated Argon2id cracking job against the password verifier — since there is no rate limiting or lockout on this offline step, they can try passwords indefinitely at whatever speed their hardware allows. Once the master password is recovered, the attacker unwraps the data key and decrypts the notebook, gaining full read access to its contents — including any proprietary notes, credentials, or context an internal AI/RAG system was using SiYuan to store and retrieve.

Weaknesses (CWE)

CWE-522 — Insufficiently Protected Credentials: The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

  • [Architecture and Design] Use an appropriate security mechanism to protect the credentials.
  • [Architecture and Design] Make appropriate use of cryptography to protect the credentials.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 3, 2026
First Seen
August 12, 2026

Related Vulnerabilities