GHSA-h64j-vrf9-jpc3HighCVSS 7.5

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts...

Published
August 16, 2026
Last Modified
August 16, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

🔗 References (4)