Information Exposure in SiYuan Prior to Version 3.7.4
CVE-2026-74799
9.2CRITICAL
What is CVE-2026-74799?
SiYuan versions prior to 3.7.4 allow unauthenticated access to debug endpoints when not operating in 'prod' mode. This misconfiguration exposes sensitive in-memory information, including AccessAuthCode and API keys from AI providers, potentially compromising the security of user data and application integrity.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
