Information Disclosure in SiYuan Document Management Software
CVE-2026-73606
6.9MEDIUM
What is CVE-2026-73606?
Versions of SiYuan prior to v3.7.4 expose an information disclosure vulnerability in the /api/block/getRefIDs endpoint. This flaw allows unauthorized users to access identifiers for blocks related to password-protected documents without the need for a password. As a result, sensitive information about the structure and references of protected documents can be retrieved by anyone, posing significant risks to user data privacy and integrity.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
