Information Disclosure in SiYuan Prior to Version 3.7.4
CVE-2026-73048
6.9MEDIUM
What is CVE-2026-73048?
SiYuan versions prior to v3.7.4 are susceptible to an information disclosure flaw. The vulnerability exists in the getRefIDsByFileAnnotationID endpoint, which unintentionally returns block identifiers linked to PDF annotations without adequate publish-access filtering. Malicious users can exploit this weakness by providing annotation identifiers from published pages, thus gaining access to block identifiers from restricted documents, which reveals citation relationships across tiers that should remain forbidden and protected by passwords.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
