LOW GitHub

CVE-2026-74802

SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass

**High** ## Package gomod `github.com/siyuan-note/siyuan/kernel` ## Affected versions 3.7.3 ## Patched versions *(none yet — leave blank until a fix is released)* ## Description ### Summary `/ws/network/proxy` is an admin-only WebSocket forward-proxy endpoint (target URL and headers fully attacker-specifiable via query parameters). Its `websocket.Upgrader` explicitly overrides `CheckOrigin` to unconditionally return `true` — disabling the origin validation that the `gorilla/websocket` libra

Affected Products

References

Published: 2026-10-02 · Source: GitHub · Feed updated: 2026-10-03
This low severity vulnerability was published on 2026-10-02 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260803045322-cb67e0b4fab5.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.