Information Disclosure in SiYuan Workspace State for Unauthenticated Users
CVE-2026-72788

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72788?

SiYuan versions prior to v3.7.4 are susceptible to an information disclosure vulnerability within the UILayout filter. This flaw allows unauthenticated attackers to exploit the getConf endpoint, leading to the unintended exposure of sensitive administrator data. Specifically, attackers can access a range of private information, including the open documents of admins, search terms, notebook paths, and asset locations without any form of authentication. Proper measures should be implemented to secure this endpoint and protect administrative data from unauthorized access.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.