Information Disclosure Vulnerability in SiYuan by SiYuan Note
CVE-2026-72795
9.2CRITICAL
What is CVE-2026-72795?
The SiYuan software, specifically versions prior to v3.7.4, has a significant information disclosure vulnerability. This weakness arises from the failure to adequately filter embedded block content by publish access within the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. As a result, attackers are able to exploit this flaw to make unauthorized requests for published blocks containing embedded queries. Consequently, they could gain access to sensitive information from password-protected, hidden, or otherwise restricted documents.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
