SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 22:16
Updated : 2026-08-26 17:04
NVD link : CVE-2026-73045
Mitre link : CVE-2026-73045
CVE.ORG link : CVE-2026-73045
JSON object : View
Products Affected
No product.
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
