THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-34fj-mwm6-fjfg (high) — SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

[GHSA] GHSA-34fj-mwm6-fjfg (high) — SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

highgithub_advisoriesPublished 2026-09-04

GHSA-34fj-mwm6-fjfg Severity: high CVE: CVE-2026-72794

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

**CVE:** This vulnerability corresponds to CVE-2026-72794.

### Summary

`/api/system/getConf` returns `Conf.CookieKey`, the key used to sign the server's session cookies in its re

Indicators of compromise

Original source: https://github.com/advisories/GHSA-34fj-mwm6-fjfg