SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go). The Publish Service runs on a separate, unauthenticated-by-default listener (default TCP port 6808) and gates named publish-viewer accounts (Conf.Publish.Auth.Accounts) with Basic Auth that has no rate limiting, per-account lockout, or backoff. Unauthenticated remote attackers can submit unlimited password guesses against named accounts to gain access to published notes/notebooks.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
SiYuan versions before 3.7.4 contain a critical authentication bypass vulnerability in the Publish Service Basic Auth implementation. The vulnerability exists because the Publish Service listener (default port 6808) enforces no rate limiting, account lockout mechanisms, or exponential backoff on authentication attempts. This allows unauthenticated remote attackers to conduct unlimited brute-force attacks against named publish-viewer accounts without operational friction. Any organization running vulnerable SiYuan instances with the Publish Service exposed is at risk of account compromise, particularly those managing sensitive documentation or collaborative workspaces where publish-viewer access provides meaningful lateral movement opportunities.
While this CVE maps to CWE-307 (Improper Restriction of Rendered UI Layers or Frames) rather than traditional MITRE ATT&CK techniques, Casky's AI-driven security skills would detect the attack patterns associated with credential compromise workflows. A practitioner using Casky would observe reconnaissance activity (T1592 - Gather Victim Identity Information) through systematic credential testing, followed by brute-force attempt clustering (T1110 - Brute Force) characterized by rapid successive authentication failures from a single source against multiple accounts or repeated attempts against single accounts. Extended reasoning across Casky's 754 mapped skills would correlate these patterns with T1078 (Valid Accounts) post-exploitation techniques, flagging when successfully compromised accounts begin accessing or exfiltrating publish content. The platform would alert defenders to the absence of authentication controls and recommend immediate patching to 3.7.4+ or network segmentation of port 6808.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-74868. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation