SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 11:16
Updated : 2026-08-26 16:57
NVD link : CVE-2026-74799
Mitre link : CVE-2026-74799
CVE.ORG link : CVE-2026-74799
JSON object : View
Products Affected
No product.
CWE
CWE-215
Insertion of Sensitive Information Into Debugging Code
