Information Disclosure Vulnerability in SiYuan Product by SiYuan
CVE-2026-72793
What is CVE-2026-72793?
Versions of SiYuan prior to v3.7.4 are susceptible to an information disclosure vulnerability found in the /api/system/getConf endpoint. This flaw arises from the failure to adequately mask sensitive configuration fields, enabling unauthorized users—such as those with anonymous or publish-reader access—to retrieve critical information including the session-cookie signing key, operating system username linked to the pandoc path, and encrypted-notebook key material. As a result, malicious actors could exploit this vulnerability to forge or modify session cookies, impersonating legitimate users. Furthermore, in configurations lacking access-auth codes, attackers could potentially escalate their privileges to that of an administrator.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
