CVE-2026-72801: SiYuan: key material leak enables offline cracking
GHSA-8x84-r2ff-h8pq HIGH PoC AVAILABLE CISA: TRACK*SiYuan, a self-hosted note-taking application some teams use as an encrypted personal knowledge base for LLM and RAG workflows, ships an unauthenticated endpoint in its publish mode that leaks the Argon2id salt, cost parameters, password verifier, and wrapped data key for encrypted notebooks. Because the attacker needs no credentials or user interaction (AV:N/PR:N/UI:N, CVSS 7.5) and can retrieve this material over the network, any internet-exposed publish-mode deployment hands adversaries everything required to brute-force the master password completely offline and without any rate limiting. Exploitation likelihood sits around the 84th EPSS percentile (0.24%) and CISA's SSVC decision is Track*, meaning it isn't flagged for emergency action but belongs on the patch backlog; there is no known KEV listing, public exploit, or Nuclei template yet. Impact is confidentiality-only (C:H/I:N/A:N), so notebook contents — which can include proprietary data feeding an AI knowledge base — are at risk of full offline decryption, not tampering or downtime. Patch to SiYuan v3.7.4+ immediately on any instance running publish mode, and until then take publish-mode endpoints off the public internet or front them with an authenticating reverse proxy.
What is the risk?
Exploitability is high in relative terms: the attack requires no authentication, no user interaction, and low complexity (AC:L) — just network reachability to a publish-mode SiYuan instance. However, this isn't a single-step compromise; the attacker must then run a compute-intensive offline Argon2id cracking job, and success depends entirely on the strength of the target's master password. Impact is confined to confidentiality (C:H) with no integrity or availability effect, but for organizations using SiYuan as an encrypted knowledge repository — including as a backend for personal or team RAG/LLM workflows — a successful crack means full plaintext access to notebook contents. Exposure is currently limited: EPSS sits at 0.24% (84th percentile), the CVE is not in CISA KEV, and no public exploit or scanner template exists, so mass exploitation is unlikely near-term. Overall risk is best characterized as moderate-and-patch-now: low current exploitation pressure, but a straightforward, well-understood attack path (leaked KDF material → unrestricted offline brute-force) that only gets easier as cracking hardware improves.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260724102025-3bc014c7dc32 | 0.0.0-20260724102025-3bc014c7dc32 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade to SiYuan v3.7.4 or later, which fixes the endpoint disclosure — this is the only complete remediation. Until patched, disable publish mode or restrict it to trusted networks/VPN rather than exposing it directly to the internet; if publish mode must remain internet-facing, front it with an authenticating reverse proxy (HTTP basic auth, OAuth proxy, etc.) so the vulnerable endpoint isn't reachable unauthenticated. Rotate the master password on any notebook that was exposed via an internet-facing publish-mode instance, since salt/verifier/wrapped-key material may already have been harvested. For detection, review web server or reverse-proxy logs for repeated unauthenticated requests to publish-mode key-material endpoints, and if SiYuan feeds an AI/RAG pipeline, audit that pipeline's access logs for unexpected bulk reads following any suspected key compromise.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72801?
SiYuan, a self-hosted note-taking application some teams use as an encrypted personal knowledge base for LLM and RAG workflows, ships an unauthenticated endpoint in its publish mode that leaks the Argon2id salt, cost parameters, password verifier, and wrapped data key for encrypted notebooks. Because the attacker needs no credentials or user interaction (AV:N/PR:N/UI:N, CVSS 7.5) and can retrieve this material over the network, any internet-exposed publish-mode deployment hands adversaries everything required to brute-force the master password completely offline and without any rate limiting. Exploitation likelihood sits around the 84th EPSS percentile (0.24%) and CISA's SSVC decision is Track*, meaning it isn't flagged for emergency action but belongs on the patch backlog; there is no known KEV listing, public exploit, or Nuclei template yet. Impact is confidentiality-only (C:H/I:N/A:N), so notebook contents — which can include proprietary data feeding an AI knowledge base — are at risk of full offline decryption, not tampering or downtime. Patch to SiYuan v3.7.4+ immediately on any instance running publish mode, and until then take publish-mode endpoints off the public internet or front them with an authenticating reverse proxy.
Is CVE-2026-72801 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72801, increasing the risk of exploitation.
How to fix CVE-2026-72801?
Upgrade to SiYuan v3.7.4 or later, which fixes the endpoint disclosure — this is the only complete remediation. Until patched, disable publish mode or restrict it to trusted networks/VPN rather than exposing it directly to the internet; if publish mode must remain internet-facing, front it with an authenticating reverse proxy (HTTP basic auth, OAuth proxy, etc.) so the vulnerable endpoint isn't reachable unauthenticated. Rotate the master password on any notebook that was exposed via an internet-facing publish-mode instance, since salt/verifier/wrapped-key material may already have been harvested. For detection, review web server or reverse-proxy logs for repeated unauthenticated requests to publish-mode key-material endpoints, and if SiYuan feeds an AI/RAG pipeline, audit that pipeline's access logs for unexpected bulk reads following any suspected key compromise.
What systems are affected by CVE-2026-72801?
This vulnerability affects the following AI/ML architecture patterns: RAG pipelines.
What is the CVSS score for CVE-2026-72801?
CVE-2026-72801 has a CVSS v3.1 base score of 7.5 (HIGH). The EPSS exploitation probability is 0.41%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0055 Unsecured Credentials Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.
Exploitation Scenario
An attacker scanning the internet for exposed SiYuan publish-mode instances (e.g., via fingerprinting the default publish UI) finds a target organization using SiYuan as a shared encrypted knowledge base, possibly one that also feeds a company RAG assistant. Without authenticating, the attacker hits the vulnerable endpoint and retrieves the Argon2id salt, cost parameters, password verifier, and wrapped data key for the target notebook. The attacker takes this material offline and runs a GPU-accelerated Argon2id cracking job against the password verifier — since there is no rate limiting or lockout on this offline step, they can try passwords indefinitely at whatever speed their hardware allows. Once the master password is recovered, the attacker unwraps the data key and decrypts the notebook, gaining full read access to its contents — including any proprietary notes, credentials, or context an internal AI/RAG system was using SiYuan to store and retrieve.
Weaknesses (CWE)
CWE-522 Insufficiently Protected Credentials
Primary
CWE-522 Insufficiently Protected Credentials
Primary
CWE-522 Insufficiently Protected Credentials CWE-522 — Insufficiently Protected Credentials: The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
- [Architecture and Design] Use an appropriate security mechanism to protect the credentials.
- [Architecture and Design] Make appropriate use of cryptography to protect the credentials.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook