THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mw8r-mw84-88v2 (high) — SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

[GHSA] GHSA-mw8r-mw84-88v2 (high) — SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

medgithub_advisoriesPublished 2026-09-03

GHSA-mw8r-mw84-88v2 Severity: high CVE: CVE-2026-72810

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

**CVE:** This vulnerability corresponds to CVE-2026-72810.

### Summary

WebSocket sessions established through the pu

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mw8r-mw84-88v2