Skip to content

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

High severity GitHub Reviewed Published Jul 23, 2026 in siyuan-note/siyuan • Updated Sep 3, 2026

Package

gomod github.com/siyuan-note/siyuan/kernel (Go)

Affected versions

< 0.0.0-20260723013612-ba948639d7f6

Patched versions

0.0.0-20260723013612-ba948639d7f6

Description

CVE: This vulnerability corresponds to CVE-2026-72810.

Summary

WebSocket sessions established through the publish surface (port 6808, RoleReader anonymous when Publish.Auth.Enable is false) are added to the same broadcast session pool as authenticated sessions. The kernel's broadcast functions push content events transactions carrying block DOM, document save/create, move/rename to every session in the pool with no role or publish-access filtering. As a result, an anonymous reader who holds a WebSocket connection open passively receives a real-time feed of every edit made in the workspace, including edits to password-protected, publish-forbidden, and unpublished documents. Because these events are delivered over the push channel and never pass through an HTTP handler, none of the publish-access filters that gate the HTTP endpoints apply.

Details

Session admission. HandleConnect admits the injected RoleReader publish token, and the session is registered via AddPushChan into the same sessions pool used for authenticated clients.

Unfiltered broadcast. The broadcast functions (Broadcast, broadcastOthers, broadcastOtherAppMains, …) write to every session in the pool with no role or publish-access check. The isPublish flag on a session is consulted only to send the "service closed" notice it is never used to gate content. Content events are pushed via PushModeBroadcast → Broadcast(), so transactions (with rendered block DOM), savedoc/create, and moveDoc/rename events reach the publish reader's socket unfiltered.

No HTTP filter applies. This is a push channel, the events originate from the kernel's own edit pipeline and are broadcast directly to open sockets. They never traverse an HTTP handler, so the publish-access filters that gate the HTTP content endpoints (and the incomplete/missing filters reported separately on those endpoints) are not in the path at all. The WebSocket route (/ws) is CheckAuth-only, which the publish RoleReader token satisfies.

Proof of Concept

Reproduced on a local instance (SiYuan running locally, publish mode enabled on port 6808, publish Basic Auth disabled). An anonymous client (no token, no password) opens wss://127.0.0.1:6808/ws and holds it open while an administrator edits documents in the workspace.

The anonymous socket received, in real time and unfiltered:

  • updateAttrs with name=WS_LEAK_SECRET_9931 on a block whose rootID is a password-protected document.
  • The secret title WS_SECRET_DOC_7742 of a newly created document.
  • The create event carrying the notebook (box) name CritChain and the document path.

No HTTP request was made beyond the WebSocket upgrade; the content arrived over the push channel.

Impact

An anonymous reader (publish mode with auth disabled) or any publish RoleReader who merely holds a WebSocket connection open receives a live feed of every edit an administrator makes: block DOM, attributes, titles, notebook names, and document structure, including for password-protected, publish-forbidden, and unpublished documents. This defeats the publish-access and publish-password boundaries entirely for any content edited while the socket is open. The precondition is trivial: an administrator active in the workspace while the anonymous socket is connected. Confidentiality-only (passive disclosure); the channel is receive-only for the reader. Encrypted-notebook content follows the same broadcast path if edited while unlocked.

Suggested fix

Filter broadcasts by session before writing: for any session flagged isPublish, apply the same publish-access/publish-ignore/publish-password checks used on the HTTP content path before pushing a content event, or exclude publish sessions from content broadcasts entirely and deliver only the events a publish viewer is authorized to see. The isPublish flag is already present on the session; it should gate content, not only the service-closed notice.

References

@88250 88250 published to siyuan-note/siyuan Jul 23, 2026
Published to the GitHub Advisory Database Sep 3, 2026
Reviewed Sep 3, 2026
Last updated Sep 3, 2026

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(24th percentile)

Weaknesses

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. Learn more on MITRE.

CVE ID

CVE-2026-72810

GHSA ID

GHSA-mw8r-mw84-88v2

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.