THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h4v5-crx2-3cv4 (high) — SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

[GHSA] GHSA-h4v5-crx2-3cv4 (high) — SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

highgithub_advisoriesPublished 2026-09-04

GHSA-h4v5-crx2-3cv4 Severity: high CVE: CVE-2026-72793

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

**CVE:** This vulnerability corresponds to CVE-2026-72793.

### Summary

`/

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h4v5-crx2-3cv4