PT-2026-26211 · Siyuan · Siyuan

·

CVE-2026-33203

·

Published

2026-03-18

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.2
Description SiYuan is a personal knowledge management system. The kernel WebSocket server accepts unauthenticated connections when a specific "auth keepalive" query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service. The issue resides in the kernel/server/serve.go file, specifically in the handling of the /ws?app=siyuan endpoint with the id=auth&type=auth query parameters. The vulnerable code accesses fields from the incoming JSON data using type assertions without validation, such as request["cmd"].(string), request["reqId"].(float64), and request["param"].(map[string]interface{}). Malformed or missing fields can trigger a runtime panic, leading to a denial of service.
Recommendations Versions prior to 3.6.2 should be updated to version 3.6.2 or later.

Exploit

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33203
GHSA-3G9H-9HP4-654V
GO-2026-4752
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Siyuan