Information Disclosure in SiYuan Product by SiYuan Technologies
CVE-2026-73630
What is CVE-2026-73630?
SiYuan versions prior to 3.7.4 are susceptible to an information disclosure flaw in the /api/filetree/authFilePublishAccess endpoint. This endpoint, which can be accessed anonymously, is primarily secured through CheckAuth but fails to implement a proper code for failed attempts, relying instead on response messages and the presence of a Set-Cookie header for signaling outcomes. An attacker can exploit this by sending requests with an empty password for specific document identifiers. This allows them to ascertain the accessibility status of documents, confirming their presence as either public, password-protected, or hidden for unauthorized access. The issuance of a publish-auth cookie for forbidden documents further exacerbates this vulnerability.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
