THREAT OPS › Threat News › [GHSA] GHSA-34fj-mwm6-fjfg (high) — SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
[GHSA] GHSA-34fj-mwm6-fjfg (high) — SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
GHSA-34fj-mwm6-fjfg Severity: high CVE: CVE-2026-72794
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
**CVE:** This vulnerability corresponds to CVE-2026-72794.
### Summary
`/api/system/getConf` returns `Conf.CookieKey`, the key used to sign the server's session cookies in its re
Indicators of compromise
- CVE-2026-72794cve
- http://127.0.0.1:6808/api/system/getConfurl
- http://127.0.0.1:6808/api/system/exportConfurl
Original source: https://github.com/advisories/GHSA-34fj-mwm6-fjfg