THREAT OPS › Threat News › [GHSA] GHSA-8x84-r2ff-h8pq (high) — SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
[GHSA] GHSA-8x84-r2ff-h8pq (high) — SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
GHSA-8x84-r2ff-h8pq Severity: high CVE: CVE-2026-72801
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
**CVE:** This vulnerability corresponds to CVE-2026-72801.
### Summary
Two `CheckAuth`-only endpoints disclose the complete offline attack
MITRE ATT&CK techniques
- Password CrackingT1110.002
Indicators of compromise
- CVE-2026-72801cve
- http://127.0.0.1:6808/api/system/getConfurl
- http://127.0.0.1:6808/api/notebook/getNotebookConfurl
Original source: https://github.com/advisories/GHSA-8x84-r2ff-h8pq