Information Disclosure Vulnerability in SiYuan Software by SiYuan Team
CVE-2026-72799
What is CVE-2026-72799?
An information disclosure vulnerability exists in SiYuan prior to version 3.7.4. This issue arises from the software's failure to enforce proper publish-access filters on multiple filetree path-resolution endpoints. As a result, unauthorized users—including unregistered or improperly authenticated individuals—can exploit these endpoints to gain access to the complete structure of private documents. Specifically, they can enumerate details such as notebook names, folder hierarchies, and document titles, which may include documents that are marked as hidden, password-protected, or restricted from publishing. This vulnerability poses significant risks as it allows for an unauthorized view of sensitive data within the application.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
