Content Disclosure Vulnerability in SiYuan by SiYuan Note
CVE-2026-68586

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-68586?

The version prior to 3.7.3 of SiYuan fails to enforce appropriate access controls for specific content endpoints, namely getBacklinkDoc and getBackmentionDoc. This oversight allows a user, including those without proper authentication, to access restricted content. While the functionality related to backlinks is secured against unauthorized access, the content endpoints are not subjected to the same protective measures. Consequently, individuals can invoke these endpoints using the IDs of documents that are supposed to be inaccessible and view their content, posing a risk of unintended data exposure.

Affected Version(s)

siyuan 0 < 3.7.3

siyuan 3.7.3

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.