Information Disclosure in SiYuan Notebook by SiYuan Technologies
CVE-2026-72790
6.9MEDIUM
What is CVE-2026-72790?
SiYuan Notebook versions prior to 3.7.4 exhibit an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint. This flaw allows unauthorized users to access sensitive notebook metadata, including names, document counts, sizes, and timestamps for notebooks that should remain confidential. The absence of necessary authorization checks enables attackers to gain insights into closed or non-published notebooks, posing a significant risk to user data privacy.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
