CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-74802

CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

Alon Barad
Alon Barad
Software Engineer

Oct 3, 2026·5 min read·1 visit

Executive Summary (TL;DR)

SiYuan is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) because its internal WebSocket handlers disable browser origin validation. This allows attackers to establish persistent tunnels, execute SSRF, and pivot into the victim's local network.

CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the SiYuan knowledge workspace application. Due to improper origin validation across multiple internal WebSocket endpoints, an attacker can hijack active authenticated sessions when a victim visits an untrusted external page. This allows the attacker to route malicious network traffic through the victim's localized SiYuan server, establishing an authenticated network pivot and facilitating Server-Side Request Forgery (SSRF).

Vulnerability Overview

SiYuan is an open-source, local-first knowledge management platform developed in Go. To support real-time data synchronization, RPC functions, and plugin communication, the application exposes several WebSocket endpoints. These endpoints run on port 6806 by default and handle highly privileged system activities.\n\nOne of the most sensitive operations exposed is the administrative network proxy endpoint, located at /ws/network/proxy. This route is designed to tunnel network traffic directly through the SiYuan kernel binary. Because this endpoint and several others lack validation controls, they represent a significant attack surface to malicious actors online.\n\nUnder standard Same-Origin Policy (SOP) rules, web browsers do not restrict cross-site WebSocket handshakes. It is the responsibility of the receiving server to validate the Origin header sent in the initial HTTP upgrade request. When this validation is omitted, any third-party script running in a user's browser can interact with the WebSocket server, bypassing conventional CORS restrictions.

Root Cause Analysis

The root cause of CVE-2026-74802 is an Origin Validation Error (CWE-346) in the initialization of the application's WebSocket upgrader instances. Specifically, within kernel/api/network.go, the CheckOrigin callback function of the gorilla/websocket library was explicitly overridden to bypass security checks.\n\nThe original implementation defined a CheckOrigin callback that unconditionally returned true. This explicit instruction forced the Go web server to accept incoming WebSocket connections regardless of the domain specified in the request's Origin header. An attacker-controlled site could thus successfully initiate a handshake.\n\nThis structural security defect extended beyond the proxy endpoint. The primary WebSocket server running inside kernel/server/serve.go used the melody library without configuring any origin checks. Likewise, the broadcast channels in kernel/api/broadcast.go and the plugin-based RPC endpoints in kernel/plugin/rpc.go used Go WebSocket Server (GWS) upgraders that lacked verification controls.

Code Analysis

In vulnerable versions of SiYuan, the network proxy endpoint was upgraded using the following structure in kernel/api/network.go:\n\ngo\n// Vulnerable: CheckOrigin returns true unconditionally\nupgrader := websocket.Upgrader{\n\tCheckOrigin: func(r *http.Request) bool { return true },\n}\nclientConn, upgradeErr := upgrader.Upgrade(c.Writer, c.Request, upgradeHeaders)\n\n\nBecause the server does not perform checks, browsers transmitting the upgrade request automatically supply any existing session cookies. The server accepts the handshake and opens a persistent TCP socket. The fixed implementation replaces this anonymous function with an origin-checking utility function:\n\ngo\n// Patched: Origin header is verified against the Host header\nupgrader := websocket.Upgrader{\n\tCheckOrigin: func(r *http.Request) bool {\n\t\treturn util.IsSessionOriginAllowed(r.Header.Get(\"Origin\"), r.Host)\n\t},\n}\nclientConn, upgradeErr := upgrader.Upgrade(c.Writer, c.Request, upgradeHeaders)\n\n\nTo ensure complete system coverage, similar checks were added across all WebSocket routers. For example, in the broadcast handler in kernel/api/broadcast.go:\n\ngo\nwebsocket := melody.New()\n// Upgrader now validates origin headers\nwebsocket.Upgrader.CheckOrigin = func(r *http.Request) bool {\n\treturn util.IsSessionOriginAllowed(r.Header.Get(\"Origin\"), r.Host)\n}\n

Exploitation Methodology

To exploit this vulnerability, an attacker must lure an authenticated SiYuan user to visit a malicious website under the attacker's control. The malicious page runs client-side JavaScript that attempts to construct a WebSocket connection back to the victim's local loopback interface.\n\nmermaid\ngraph LR\n AttackerHost[\"Attacker Page (evil.com)\"] -- \"1. Serves exploit JS\" --> VictimBrowser[\"Victim's Browser\"]\n VictimBrowser -- \"2. WS Handshake (Origin: evil.com)\" --> SiYuan[\"SiYuan (localhost:6806)\"]\n SiYuan -- \"3. Returns Connection Accepted (101)\" --> VictimBrowser\n VictimBrowser -- \"4. Sends malicious proxy connect\" --> SiYuan\n SiYuan -- \"5. Exploit connects internal DB\" --> InternalService[\"Internal Network (192.168.1.50)\"]\n\n\nBecause the application is running locally on port 6806, the exploit script targets ws://127.0.0.1:6806/ws/network/proxy. Once the connection is open, the attacker sends control messages specifying target internal hosts. The local SiYuan Go binary acts as a forward proxy, connecting to localized targets and returning raw responses back to the attacker's script.

Impact Assessment

The CVSS base score of 8.2 reflects the significant threat this flaw poses to host environments. Because the target is typically a local installation on a user's workstation or a container inside a private network segment, successful exploitation facilitates pivoting.\n\nAttackers can leverage the compromised connection to perform port scanning against the local host and adjacent LAN environments. They can also target internal services, such as database administration interfaces or cloud instance metadata services (IMDS), which are normally protected behind perimeter firewalls.\n\nThis attack sequence requires zero authentication from the attacker's perspective, as it leverages the victim's ambient browser authentication. It results in high confidentiality loss and moderate integrity loss, with the compromised host performing unauthorized actions under the identity of the authenticated user.

Remediation & Mitigation Guidance

The primary remediation strategy is upgrading the SiYuan installation to version 3.7.4 or later. In these updated versions, the developers implemented rigorous checking routines via IsSessionOriginAllowed to confirm the request origin matches the allowed deployment host.\n\nFor environments where patching cannot be immediately completed, administrators should apply local network mitigations. Restrict access to port 6806 by binding the application service specifically to 127.0.0.1 rather than 0.0.0.0. Implement local firewall policies (iptables or Windows Firewall) to drop incoming external connections on this port.\n\nTo monitor for potential exploitation attempts, security operations teams should analyze proxy logs for WebSocket upgrade requests where the Origin header contains an external, unknown, or null value. Additionally, inspect local process execution logs to detect unexpected outbound traffic originating from the SiYuan binary.

Official Patches

SiYuanFix commit for CSWSH vulnerability

Fix Analysis (1)

Technical Appendix

CVSS Score
8.2/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS Probability
0.16%
Top 95% most exploited

Affected Systems

SiYuan (Self-Hosted & Local Deployments)

Affected Versions Detail

Product
Affected Versions
Fixed Version
SiYuan
SiYuan
< 3.7.43.7.4
AttributeDetail
CWE IDCWE-346 (Origin Validation Error)
Attack VectorNetwork (AV:N)
CVSS v3.1 Score8.2
EPSS Score0.00164
Exploit StatusProof-of-Concept
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1566Phishing
Initial Access
T1190Exploit Public-Facing Application
Initial Access
T1557Adversary-in-the-Middle (AiTM)
Credential Access
T1090Proxy / Connection Proxy
Command and Control
CWE-346
Origin Validation Error

The software does not properly validate or verify that the origin of a request is correct or expected.

Known Exploits & Detection

GitHub AdvisoryDetails on the Cross-Site WebSocket Hijacking vulnerability.

Vulnerability Timeline

Security fix commit cb67e0b4fab57c9c5f458c1fd0df5ecf4417b696 submitted by developers
2026-08-03
CVE-2026-74802 published to the National Vulnerability Database (NVD)
2026-08-17
Authoritative vendor advisory GHSA-3cc2-h3v6-rqpq published
2026-08-17
NVD record modified with finalized vulnerability intelligence data
2026-08-28

References & Sources

  • [1]GitHub Security Advisory (GHSA-3cc2-h3v6-rqpq)
  • [2]Official Fix Commit
  • [3]CVE Record (CVE.org)
  • [4]Third-Party Security Advisory (VulnCheck)
  • [5]SiYuan Release Tag v3.8.0
Related Vulnerabilities
CVE-2026-74802

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•CVE-2026-74904
8.7

CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

A high-severity missing authorization vulnerability (CWE-862) exists in the SiYuan note-taking application before v3.7.4. Seventeen block metadata and content-derived endpoints within kernel/api/block.go lack proper publish-access and role-based checks. This allows low-privilege or anonymous users in publish mode to bypass workspace restrictions and disclose private block content, trace workspace structures, map document indexes, and verify the existence of private notes. The vulnerability is addressed in version v3.7.4.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 2 hours ago•CVE-2026-71416
8.8

CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

A critical cross-site WebSocket hijacking (CSWSH) vulnerability in headroomlabs-ai/headroom prior to version 0.35.0 allows unauthorized external origins to establish connection channels to the Headroom proxy, enabling arbitrary prompt execution and remote code execution through local tool integration.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 3 hours ago•GHSA-CJCG-CXMH-9WCR
7.5

GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

A critical vulnerability exists in the praxis-proxy library where the omission of default limits on HTTP/2 server options allows remote attackers to trigger a Denial of Service (DoS) using an HPACK compression bomb and flow-control window stalls. This vulnerability is cataloged as GHSA-cjcg-cxmh-9wcr.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 5 hours ago•GHSA-MWM8-39RW-8826
8.1

GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

A Use-After-Free (UAF) vulnerability exists in the sqlite3-ruby native C extension when marshaling arguments for user-defined SQLite aggregate functions with multiple arguments. Due to temporary heap-allocated argument arrays not being registered with the Ruby Garbage Collector, active objects can be prematurely reclaimed, resulting in memory corruption or process-level crashes.

Alon Barad
Alon Barad
5 views•7 min read
•about 5 hours ago•CVE-2026-19484
7.5

CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

An unauthenticated remote denial of service vulnerability exists in @fastify/busboy versions 3.1.0 through 3.2.0. The vulnerability is caused by an integer wrap-around in the Boyer-Moore-Horspool algorithm implementation inside the sbmh submodule when initializing skip distances. When processing a specific boundary of 252 bytes, the parser triggers an infinite loop, stalling the single-threaded Node.js event loop and exhausting CPU resources.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•CVE-2026-19481
7.5

CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like __proto__ or constructor), the internal HeaderParser triggers a synchronous TypeError.

Amit Schendel
Amit Schendel
4 views•7 min read