HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-72801 — SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation materia...
·Source: NIST NVD
Updated:
Executive Summary
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.
Analysis
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting. CVSS Score: 7.5. Published: 2026-08-12T20:17:51.973.