Disclosure summary
**High** ## Package gomod `github.com/siyuan-note/siyuan/kernel` ## Affected versions 3.7.3 ## Patched versions *(none yet — leave blank until a fix is released)* ## Description ### Summary `/ws/network/proxy` is an admin-only WebSocket forward-proxy endpoint (target URL and headers fully attacker-specifiable via query parameters). Its `websocket.Upgrader` explicitly overrides `CheckOrigin` to unconditionally return `true` — disabling the origin validation that the `gorilla/websocket` library otherwise enforces **by default**. WebSocket handshake requests are not subject to CORS preflight at all (unlike `fetch`/XHR), so origin validation for WebSocket endpoints has to be done deliberately by the server; here it has been deliberately turned *off* instead. Combined with the endpoint's own query-parameter-driven proxy target, this is a textbook Cross-Site WebSocket Hijacking (CSWSH) primitive on a capability that amounts to an authenticated network pivot through the SiYuan kernel process. ### Details ```go // kernel/api/network.go:501 upgrader := websocket.Upgrader{ CheckOrigin: func(r *http.Request) bool { return true }, } clientConn, upgradeErr := upgrader.Upgrade(c.Writer, c.Reques
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-3cc2-h3v6-rqpq
Open original source · Updated Oct 02, 2026
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Source severity: LOW / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/siyuan-note/siyuan/kernel | < 0.0.0-20260803045322-cb67e0b4fab5 | 0.0.0-20260803045322-cb67e0b4fab5 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-02T18:46:18-04:00
MODIFIED 2026-10-02T18:46:19-04:00
INGESTED 2026-10-06T11:45:17-04:00