Summary
CVE-2026-73056 is a critical vulnerability in SiYuan Note (a personal knowledge management application) where the kernel’s CheckAuth() authentication middleware fails to apply any brute-force protection when API tokens are submitted via Authorization headers or token query parameters. This allows an unauthenticated attacker to make unlimited automated guesses against the configured API token, potentially gaining full administrator access to the instance. The flaw affects all versions prior to 3.7.4 and carries a CVSS score of 9.3 (v4.0) / 9.8 (v3.1), both rated Critical.
Technical details
- Root cause: The
CheckAuth()middleware validates API tokens submitted viaAuthorization: Token/Bearerheaders or?token=query parameters, but these code branches never reference the application’sWrongAuthCounttracking orNeedCaptcha()lockout logic that protects the standard login (LoginAuth()) path. - Additional weaknesses: The
setAPIToken()function accepts any string as a token with no minimum length or complexity requirement, and token comparison is performed with a plain Go string equality check (==) rather than a constant-time comparison, introducing a timing side-channel. - Trigger conditions: The target SiYuan kernel must be network-reachable and have API token authentication configured (including short/weak tokens set for integrations).
- Attack vector: Network — no authentication or user interaction required.
- Impact: Successful brute-force of the API token grants complete
RoleAdministratorprivileges, enabling arbitrary file access, SQL execution, and process control on the host.
Affected software
- SiYuan (siyuan-note/siyuan) kernel — all versions prior to 3.7.4
Severity
- CVSS v3.1 Base Score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 Base Score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade SiYuan to version 3.7.4 or later, which restores throttling/lockout protection on API token authentication.
- If patching is not immediately possible:
- Set a high-entropy, long API token (16+ random characters) rather than a short custom value.
- Avoid exposing the SiYuan kernel directly to the internet; restrict access to trusted networks or place it behind a VPN.
- Disable API token authentication entirely if it is not required for integrations.

