Information Disclosure in SiYuan Versions up to 3.7.2
CVE-2026-72808

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72808?

SiYuan versions up to v3.7.2 are susceptible to an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint. This flaw allows unauthorized access to private PDF annotations, such as highlights and notes, from publish-forbidden, password-protected, or unpublished documents. The endpoint lacks necessary access controls, being accessible even to anonymous users or those with limited roles. However, this issue does not extend to encrypted notebooks, where annotations remain secure. Users are advised to upgrade to v3.7.4 or later to mitigate this vulnerability.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.