Metadata Disclosure Vulnerability in SiYuan by SiYuan
CVE-2026-68585

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-68585?

Versions of SiYuan prior to v3.7.3 are susceptible to a metadata disclosure vulnerability that affects the /api/block/getBlockInfo endpoint. This vulnerability permits unauthorized access to document root metadata, including titles of documents classified as publish-forbidden. Attackers can leverage anonymous access or publish RoleReader tokens to query the block ID, effectively exposing sensitive information such as notebook details, paths, root IDs, and icons for documents intended to remain unpublished. Proper access control measures are crucial to prevent unauthorized data exposure.

Affected Version(s)

siyuan 0 < 3.7.3

siyuan 3.7.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.