Information Disclosure Vulnerability in SiYuan Software by SiYuan Team
CVE-2026-72799

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72799?

An information disclosure vulnerability exists in SiYuan prior to version 3.7.4. This issue arises from the software's failure to enforce proper publish-access filters on multiple filetree path-resolution endpoints. As a result, unauthorized users—including unregistered or improperly authenticated individuals—can exploit these endpoints to gain access to the complete structure of private documents. Specifically, they can enumerate details such as notebook names, folder hierarchies, and document titles, which may include documents that are marked as hidden, password-protected, or restricted from publishing. This vulnerability poses significant risks as it allows for an unauthorized view of sensitive data within the application.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.