Summary
CVE-2026-73045 is an improper restriction of excessive authentication attempts vulnerability (CWE-307) affecting SiYuan Note prior to version 3.7.4. The authFilePublishAccess endpoint, which validates the password for a password-protected "Publish" notebook, imposes no rate limiting, attempt counter, or CAPTCHA, allowing an unauthenticated remote attacker to brute-force a notebook’s publish password. The issue carries a CVSS v4.0 score of 8.7 (High).
Technical details
- Root cause: the
POST /api/filetree/authFilePublishAccessendpoint (kernel/api/filetree.go) accepts unlimited password-guess attempts with no throttling, lockout, or CAPTCHA challenge. - The password check is additionally implemented as a plain string comparison rather than a constant-time comparison, introducing a secondary observable timing discrepancy (CWE-208).
- Trigger conditions: a notebook must be published via SiYuan’s "Publish" feature and protected with a password; no authentication, privileges, or user interaction are required to attack the endpoint.
- Attack vector: network — the endpoint is intentionally exposed to unauthenticated callers by design, since it exists to gate public access to published notebooks.
- Impact: successful brute-forcing exposes the confidentiality of the targeted published notebook’s content. Impact is scoped to the individual notebook and does not grant broader workspace or administrative access.
Affected software
- SiYuan Note: all versions prior to 3.7.3 (inclusive) — i.e., all versions before 3.7.4.
Severity
- CVSS v3.1 Base Score: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v4.0 Base Score: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: upgrade SiYuan Note to version 3.7.4 or later, which implements rate limiting and secure password validation on the publish-access endpoint.
- If patching is not immediately possible: avoid password-protecting published notebooks containing sensitive content until upgraded, or restrict network access to the SiYuan instance (e.g., via VPN, IP allow-listing, or a reverse proxy with rate limiting) to reduce exposure to brute-force attempts.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Access Authorization - SiYuan,思源笔记 - Raw response body:
exitSiYuan,b3log.org/siyuan

