CVE-2026-74802: CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace
CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace Vulnerability ID: CVE-2026-74802 CVSS Score: 8.2 Published: 2026-10-02 CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking
CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace
Vulnerability ID: CVE-2026-74802
CVSS Score: 8.2
Published: 2026-10-02
CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the SiYuan knowledge workspace application. Due to improper origin validation across multiple internal WebSocket endpoints, an attacker can hijack active authenticated sessions when a victim visits an untrusted external page. This allows the attacker to route malicious network traffic through the victim's localized SiYuan server, establishing an authenticated network pivot and facilitating Server-Side Request Forgery (SSRF).
TL;DR
SiYuan is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) because its internal WebSocket handlers disable browser origin validation. This allows attackers to establish persistent tunnels, execute SSRF, and pivot into the victim's local network.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-346 (Origin Validation Error)
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 8.2
- EPSS Score: 0.00164
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- SiYuan (Self-Hosted & Local Deployments)
-
SiYuan: < 3.7.4 (Fixed in:
3.7.4)
Code Analysis
Commit: cb67e0b
Fix Cross-Site WebSocket Hijacking (CSWSH) vulnerabilities by validating origin headers
Exploit Details
- GitHub Advisory: Details on the Cross-Site WebSocket Hijacking vulnerability.
Mitigation Strategies
- Upgrade SiYuan to version 3.7.4 or higher to enforce origin verification checks.
- Restrict network access to port 6806 using local firewall configurations.
- Avoid browsing untrusted sites while keeping an active administrative session open in the background.
Remediation Steps:
- Download and install the latest SiYuan release (version 3.7.4 or later) from the official repository.
- Verify the version update by accessing the internal configuration menu.
- Configure the application bound address to 127.0.0.1 to limit local loopback communication.
References
- GitHub Security Advisory (GHSA-3cc2-h3v6-rqpq)
- Official Fix Commit
- CVE Record (CVE.org)
- Third-Party Security Advisory (VulnCheck)
- SiYuan Release Tag v3.8.0
Read the full report for CVE-2026-74802 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.