Authentication Bypass in SiYuan Product by SiYuan Note
CVE-2026-72804
9.2CRITICAL
What is CVE-2026-72804?
In SiYuan versions prior to v3.7.4, a security flaw exists that allows unauthenticated individuals to access block-level content of password-protected documents. The vulnerability occurs due to inadequate validation in the getGraph and getLocalGraph endpoints, enabling attackers to exploit these endpoints without entering a password. This exposes sensitive document content and the complete reference topology to unauthorized users.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
