Information Disclosure in SiYuan Versions by SiYuan Team
CVE-2026-72798
9.2CRITICAL
What is CVE-2026-72798?
SiYuan versions prior to v3.7.4 are susceptible to an information disclosure vulnerability. The problem lies in the renderAttributeView functionality, which inadequately filters related-database content. This weakness allows unauthorized users, including anonymous readers, to access data from Relation and Rollup cells in hidden or password-protected databases. By exploiting this vulnerability, attackers can request published databases that are associated with restricted databases, thereby retrieving sensitive content. This can potentially lead to the bypassing of intended row filtering mechanisms, especially when the first column of a database is not of a blocking type.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
