LOW GitHub
CVE-2026-74802
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
**High**
## Package
gomod `github.com/siyuan-note/siyuan/kernel`
## Affected versions
3.7.3
## Patched versions
*(none yet — leave blank until a fix is released)*
## Description
### Summary
`/ws/network/proxy` is an admin-only WebSocket forward-proxy endpoint (target URL and headers fully attacker-specifiable via query parameters). Its `websocket.Upgrader` explicitly overrides `CheckOrigin` to unconditionally return `true` — disabling the origin validation that the `gorilla/websocket` libra
Affected Products
- go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260803045322-cb67e0b4fab5
References
- https://github.com/advisories/GHSA-3cc2-h3v6-rqpq
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-3cc2-h3v6-rqpq
- https://nvd.nist.gov/vuln/detail/CVE-2026-74802
- https://github.com/siyuan-note/siyuan/commit/cb67e0b4fab57c9c5f458c1fd0df5ecf4417b696
This low severity vulnerability was published on 2026-10-02 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260803045322-cb67e0b4fab5.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.