Information Disclosure in SiYuan by SiYuan Technology
CVE-2026-72797

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72797?

Versions of SiYuan prior to v3.7.4 are susceptible to an information disclosure vulnerability through the getEncryptedNotebookStatus endpoint. This flaw allows anonymous readers and accounts with publish-mode permissions to access sensitive details about encrypted notebooks. Specifically, it exposes encrypted notebook identifiers, names, and their respective lock states, which could enable unauthorized enumeration of all encrypted notebooks along with insights into their decryption status stored in memory, ironically compromising the confidentiality of user data.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.