Information Disclosure Vulnerability in SiYuan Product by SiYuan Inc.
CVE-2026-72803
6.9MEDIUM
What is CVE-2026-72803?
Versions of SiYuan prior to v3.7.4 lack essential publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. This oversight allows attackers to exploit the system by sending crafted POST requests containing block IDs, thereby gaining unauthorized access to sensitive block attributes, including names, aliases, memos, and custom fields from secured documents. This vulnerability highlights the importance of robust access control mechanisms to protect sensitive user data.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
