PT-2025-53613 · Siyuan · Siyuan

28Hus

·

Published

2025-12-27

·

Updated

2025-12-27

·

CVE-2025-68948

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.5.1
Description SiYuan Note application uses a hardcoded cryptographic secret for its session store, making session encryption ineffective. The AccessAuthCode, stored in the session cookie, can be decrypted by an attacker who obtains the encrypted session cookie. This allows the attacker to retrieve the AccessAuthCode in plain text and potentially authenticate or take over the session.
Recommendations Update to a version later than 3.5.1.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-68948
GHSA-F7PH-RC3W-QP28

Affected Products

Siyuan