SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is stored within the session cookie, an attacker who intercepts or obtains a user's encrypted session cookie (e.g., via session hijacking) can locally decrypt it using the public key. Once decrypted, the attacker can retrieve the AccessAuthCode in plain text and use it to authenticate or take over the session.
History

Sat, 27 Dec 2025 00:45:00 +0000

Type Values Removed Values Added
Description SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is stored within the session cookie, an attacker who intercepts or obtains a user's encrypted session cookie (e.g., via session hijacking) can locally decrypt it using the public key. Once decrypted, the attacker can retrieve the AccessAuthCode in plain text and use it to authenticate or take over the session.
Title SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-27T00:21:31.864Z

Reserved: 2025-12-26T16:36:24.151Z

Link: CVE-2025-68948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-27T01:15:42.720

Modified: 2025-12-27T01:15:42.720

Link: CVE-2025-68948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.