PT-2025-53613 · Siyuan · Siyuan
28Hus
·
Published
2025-12-27
·
Updated
2025-12-27
·
CVE-2025-68948
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.5.1
Description
SiYuan Note application uses a hardcoded cryptographic secret for its session store, making session encryption ineffective. The AccessAuthCode, stored in the session cookie, can be decrypted by an attacker who obtains the encrypted session cookie. This allows the attacker to retrieve the AccessAuthCode in plain text and potentially authenticate or take over the session.
Recommendations
Update to a version later than 3.5.1.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siyuan