GHSA-9f49-xx3h-chx9HighCVSS 5.9

SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password.

🔗 References (6)