HomeSecuritySiYuan Publication Codes: Critical Control Point Void Allows Brute-Force

SiYuan Publishing Codes: Critical Control Point Vulnerability Allows Brute-Force

SiYuan publishing passwords can become an easy target when the audit mechanism does not limit failed attempts. CVE-2026-73045 allows unidentified remote users to repeatedly try passwords for protected notebooks.

SiYuan publishing codes and access control

The CVE Alert entry rates the issue as high severity, with a CVSS score of 7.5 . The vulnerability affects the authFilePublishAccess endpoint , which is used when SiYuan checks whether a visitor can view a published file or notebook.

The problem is different than a simple link leak. SiYuan publishing codes act as a separate layer of control for content that has already been enabled for publishing, so their security also depends on how the service responds to failed tests. When the response remains fast and repeatable, an automated tool can test a large dictionary of hypotheses.

See also: CVE-2026-66012: SiYuan vulnerability exposes MCP tools

How SiYuan publication codes are exposed

According to the technical description, SiYuan versions prior to 3.7.4 do not implement a proper threshold for failed attempts to this point. There is no delay mechanism, account lockout, or CAPTCHA to systematically slow down the tests. Thus, an attacker can automate many cases without having previously logged in.

The target is not the central server password, but the individual passwords that protect published notebooks. If any of these are short, reused, or based on a predictable word, the likelihood of success increases. Access can reveal content that the administrator intended to share only with specific recipients.

The SecNews technical team notes that the presence of the publishing function does not in itself mean a breach. CVE describes the possibility of a brute-force attack, not confirmed access to each installation. The actual risk depends on whether the publishing service is exposed to the Internet, the quality of the codes, and the type of notebooks hosted.

Brute-force control in SiYuan

What CVE-2026-73045 means for administrators

Administrators should first note the version they are running and check if the installation is prior to 3.7.4. The official SiYuan project release page on GitHub lists newer releases, but the release notes do not explicitly attribute each individual fix to CVE-2026-73045. Therefore, the upgrade should be done according to the project's guidelines and confirmed in a test environment.

Also check if the service is running directly on a public address or behind a reverse proxy. The difference affects who can send requests, but it does not replace the need for an updated version. Isolation reduces exposure, while upgrading addresses the cause of the problem.

Until the upgrade is complete, restrict the publishing service with network rules or a reverse server so that it is only accessible from necessary networks. Change SiYuan publishing passwords to long, unique phrases and avoid using them on other services. Also, keep logs of requests to authFilePublishAccess and look for unusual sequences of failed attempts.

The upgrade should not be treated as a typical version change. Before applying it, back up your workspace and check for any add-ons or customizations that affect the publishing service. After the change, test both a protected notebook and a public one to confirm that access works as expected and that failed attempts are logged.

SiYuan publishing codes should be changed immediately when notebooks contain internal notes, customer information, or product designs. If a large series of failed requests is detected, examine the time points, IP addresses, and accounts affected. Do not consider the absence of a successful login as sufficient evidence that content was not read.

See also: LudusMCP SSRF: CVE-2026-19367 exposes internal services

Protecting published notebooks SiYuan

Practical defense against vulnerability

The safest approach is a combination of upgrading to a supported version, limiting network exposure, and re-verifying all SiYuan publishing passwords. Organizations should also consider whether each notebook needs to remain publicly available and remove old publications that no longer serve a business purpose. A password can be strong, but it can be redundant if the content no longer needs to be accessible.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: claude-sesh tool: path traversal in Claude Code files

Upgrade and defense in SiYuan

CVE-2026-73045 is a reminder that a publishing mechanism may need the same attention as a basic admin login. SiYuan publishing codes, timely upgrade, and tracking of failed requests significantly limit the scope for automated testing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS