Information Disclosure in SiYuan Product by SiYuan Technologies
CVE-2026-73630

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-73630?

SiYuan versions prior to 3.7.4 are susceptible to an information disclosure flaw in the /api/filetree/authFilePublishAccess endpoint. This endpoint, which can be accessed anonymously, is primarily secured through CheckAuth but fails to implement a proper code for failed attempts, relying instead on response messages and the presence of a Set-Cookie header for signaling outcomes. An attacker can exploit this by sending requests with an empty password for specific document identifiers. This allows them to ascertain the accessibility status of documents, confirming their presence as either public, password-protected, or hidden for unauthorized access. The issuance of a publish-auth cookie for forbidden documents further exacerbates this vulnerability.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.