THREAT OPS › Threat News › [GHSA] GHSA-h4v5-crx2-3cv4 (high) — SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
[GHSA] GHSA-h4v5-crx2-3cv4 (high) — SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
GHSA-h4v5-crx2-3cv4 Severity: high CVE: CVE-2026-72793
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
**CVE:** This vulnerability corresponds to CVE-2026-72793.
### Summary
`/
Indicators of compromise
- CVE-2026-72793cve
- http://127.0.0.1:6808/api/system/getConfurl
- http://127.0.0.1:6808/api/system/exportConfurl
Original source: https://github.com/advisories/GHSA-h4v5-crx2-3cv4