Information Disclosure in SiYuan Versions up to 3.7.2
CVE-2026-72808
6.9MEDIUM
What is CVE-2026-72808?
SiYuan versions up to v3.7.2 are susceptible to an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint. This flaw allows unauthorized access to private PDF annotations, such as highlights and notes, from publish-forbidden, password-protected, or unpublished documents. The endpoint lacks necessary access controls, being accessible even to anonymous users or those with limited roles. However, this issue does not extend to encrypted notebooks, where annotations remain secure. Users are advised to upgrade to v3.7.4 or later to mitigate this vulnerability.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
