Information Disclosure Vulnerability in SiYuan by SiYuan Note
CVE-2026-68587
9.2CRITICAL
What is CVE-2026-68587?
SiYuan versions prior to v3.7.3 exhibit an information disclosure vulnerability within the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints. This flaw allows unauthorized users, including anonymous readers and RoleReader tokens, to access rendered block DOMs without proper publish-access checks. Consequently, attackers can exploit this vulnerability to retrieve the full rendered content of documents that are intended to remain restricted.
Affected Version(s)
siyuan 0 < 3.7.3
siyuan 3.7.3
