Information Disclosure in SiYuan Workspace State for Unauthenticated Users
CVE-2026-72788
6.9MEDIUM
What is CVE-2026-72788?
SiYuan versions prior to v3.7.4 are susceptible to an information disclosure vulnerability within the UILayout filter. This flaw allows unauthenticated attackers to exploit the getConf endpoint, leading to the unintended exposure of sensitive administrator data. Specifically, attackers can access a range of private information, including the open documents of admins, search terms, notebook paths, and asset locations without any form of authentication. Proper measures should be implemented to secure this endpoint and protect administrative data from unauthorized access.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
