Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-74802: CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace Vulnerability ID: CVE-2026-74802 CVSS Score: 8.2 Published: 2026-10-02 CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking

CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

Vulnerability ID: CVE-2026-74802
CVSS Score: 8.2
Published: 2026-10-02

CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the SiYuan knowledge workspace application. Due to improper origin validation across multiple internal WebSocket endpoints, an attacker can hijack active authenticated sessions when a victim visits an untrusted external page. This allows the attacker to route malicious network traffic through the victim's localized SiYuan server, establishing an authenticated network pivot and facilitating Server-Side Request Forgery (SSRF).

TL;DR

SiYuan is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) because its internal WebSocket handlers disable browser origin validation. This allows attackers to establish persistent tunnels, execute SSRF, and pivot into the victim's local network.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-346 (Origin Validation Error)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 8.2
  • EPSS Score: 0.00164
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • SiYuan (Self-Hosted & Local Deployments)
  • SiYuan: < 3.7.4 (Fixed in: 3.7.4)

Code Analysis

Commit: cb67e0b

Fix Cross-Site WebSocket Hijacking (CSWSH) vulnerabilities by validating origin headers

Exploit Details

  • GitHub Advisory: Details on the Cross-Site WebSocket Hijacking vulnerability.

Mitigation Strategies

  • Upgrade SiYuan to version 3.7.4 or higher to enforce origin verification checks.
  • Restrict network access to port 6806 using local firewall configurations.
  • Avoid browsing untrusted sites while keeping an active administrative session open in the background.

Remediation Steps:

  1. Download and install the latest SiYuan release (version 3.7.4 or later) from the official repository.
  2. Verify the version update by accessing the internal configuration menu.
  3. Configure the application bound address to 127.0.0.1 to limit local loopback communication.

References

Read the full report for CVE-2026-74802 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.