SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
SiYuan is a popular open-source note-taking application that, prior to version 3.7.4, inadvertently exposed Go runtime debugging endpoints through its net/http/pprof interface. When the application runs without the --mode flag explicitly set to 'prod', these debug endpoints (/debug/pprof/heap, /debug/pprof/goroutine, etc.) become accessible without authentication. This creates a critical vulnerability because attackers can remotely access heap dumps and memory snapshots containing highly sensitive data such as authentication codes, session tokens, and API keys for AI providers. Organizations running SiYuan instances—particularly those using it for documentation, knowledge management, or development—face immediate risk of credential compromise and lateral movement attacks if exposed to untrusted networks.
While this CVE lacks direct MITRE ATT&CK technique mapping, Casky's skill-based detection framework would identify the attack patterns within the broader reconnaissance and credential access kill chains. Practitioners using Casky would observe alerts related to suspicious HTTP requests to debug endpoints, unauthenticated access to memory inspection tools, and extraction of sensitive strings from process memory. The platform's extended reasoning capabilities—leveraging Claude AI across 754 mapped security skills—would correlate unusual /debug/pprof requests with subsequent API key usage or authentication anomalies, surfacing this as a high-priority finding. Organizations would receive actionable guidance on detecting when attackers probe for unprotected debug interfaces and exfiltrate in-memory secrets, enabling rapid containment before credentials are weaponized.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-74799. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation