THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8x84-r2ff-h8pq (high) — SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

[GHSA] GHSA-8x84-r2ff-h8pq (high) — SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

highgithub_advisoriesPublished 2026-09-03

GHSA-8x84-r2ff-h8pq Severity: high CVE: CVE-2026-72801

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

**CVE:** This vulnerability corresponds to CVE-2026-72801.

### Summary

Two `CheckAuth`-only endpoints disclose the complete offline attack

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8x84-r2ff-h8pq