Content Disclosure Vulnerability in SiYuan by SiYuan Note
CVE-2026-68586
9.2CRITICAL
What is CVE-2026-68586?
The version prior to 3.7.3 of SiYuan fails to enforce appropriate access controls for specific content endpoints, namely getBacklinkDoc and getBackmentionDoc. This oversight allows a user, including those without proper authentication, to access restricted content. While the functionality related to backlinks is secured against unauthorized access, the content endpoints are not subjected to the same protective measures. Consequently, individuals can invoke these endpoints using the IDs of documents that are supposed to be inaccessible and view their content, posing a risk of unintended data exposure.
Affected Version(s)
siyuan 0 < 3.7.3
siyuan 3.7.3
