Information Disclosure in SiYuan Versions by SiYuan Team
CVE-2026-72798

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72798?

SiYuan versions prior to v3.7.4 are susceptible to an information disclosure vulnerability. The problem lies in the renderAttributeView functionality, which inadequately filters related-database content. This weakness allows unauthorized users, including anonymous readers, to access data from Relation and Rollup cells in hidden or password-protected databases. By exploiting this vulnerability, attackers can request published databases that are associated with restricted databases, thereby retrieving sensitive content. This can potentially lead to the bypassing of intended row filtering mechanisms, especially when the first column of a database is not of a blocking type.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.