AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-74802.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSLOW / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

**High** ## Package gomod `github.com/siyuan-note/siyuan/kernel` ## Affected versions 3.7.3 ## Patched versions *(none yet — leave blank until a fix is released)* ## Description ### Summary `/ws/network/proxy` is an admin-only WebSocket forward-proxy endpoint (target URL and headers fully attacker-specifiable via query parameters). Its `websocket.Upgrader` explicitly overrides `CheckOrigin` to unconditionally return `true` — disabling the origin validation that the `gorilla/websocket` library otherwise enforces **by default**. WebSocket handshake requests are not subject to CORS preflight at all (unlike `fetch`/XHR), so origin validation for WebSocket endpoints has to be done deliberately by the server; here it has been deliberately turned *off* instead. Combined with the endpoint's own query-parameter-driven proxy target, this is a textbook Cross-Site WebSocket Hijacking (CSWSH) primitive on a capability that amounts to an authenticated network pivot through the SiYuan kernel process. ### Details ```go // kernel/api/network.go:501 upgrader := websocket.Upgrader{ CheckOrigin: func(r *http.Request) bool { return true }, } clientConn, upgradeErr := upgrader.Upgrade(c.Writer, c.Reques

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-3cc2-h3v6-rqpq

Open original source · Updated Oct 02, 2026

SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass

Source severity: LOW / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/siyuan-note/siyuan/kernel< 0.0.0-20260803045322-cb67e0b4fab50.0.0-20260803045322-cb67e0b4fab5

Original records & references

PUBLISHED 2026-10-02T18:46:18-04:00
MODIFIED 2026-10-02T18:46:19-04:00
INGESTED 2026-10-06T11:45:17-04:00