GHSA-34fj-mwm6-fjfg: SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
highvulnerability
security
Summary
SiYuan's `/api/system/getConf` endpoint returns `Conf.CookieKey` (the secret key used to sign session cookies) to anonymous users or unauthenticated readers when publish mode is enabled. An attacker with this key can forge valid session cookies and impersonate users, even though a similar endpoint (`exportConf`) in the same file deliberately removes this secret before returning configuration data.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.2%
Patch Available
Yes
Disclosure Date
September 4, 2026
Classification
Attack SophisticationTrivial
Affected Packages
github.com/siyuan-note/siyuan/kernel@< 0.0.0-20260725123945-77421530be4a (fixed: 0.0.0-20260725123945-77421530be4a)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-34fj-mwm6-fjfg
First tracked: September 4, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%