PatchSiren cyber security CVE debrief
CVE-2026-72795 siyuan-note CVE debrief
SiYuan versions before v3.7.4 are vulnerable to unauthorized access due to a failure in filtering embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. This allows attackers to read content from password-protected, hidden, or forbidden documents without authorization. The CVE record was published on 2026-08-12T20:17:51.137Z and has not been modified since then. The NVD entry is currently Deferred. Users of SiYuan versions before v3.7.4, administrators of systems using SiYuan, and security teams responsible for vulnerability management should be aware of this critical vulnerability with a CVSS score of 9.2.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-26
Who should care
Users of SiYuan versions before v3.7.4, administrators of systems using SiYuan, and security teams responsible for vulnerability management should be aware of this critical vulnerability. They should prioritize patching to version v3.7.4 or later and restrict access to published blocks containing embed queries. Additionally, they should monitor for suspicious requests to published blocks and review compensating controls for exposed systems while remediation is scheduled and verified. This vulnerability can lead to unauthorized access to sensitive content, making it essential for affected organizations to take immediate action. The CVE record was published on 2026-08-12T20:17:51.137Z and has not been modified since then. The NVD entry is currently Deferred, emphasizing the need for caution and prompt action. Security teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is crucial. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is also essential. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are critical steps in managing this vulnerability effectively. The vulnerability's impact can be significant, and a proactive approach is necessary to mitigate potential risks. By taking immediate action and following recommended steps, organizations can minimize the risk of unauthorized access to sensitive content. It is also important to note that the source detail is limited, and further verification is needed to confirm the vulnerability's impact. Therefore, a thorough review of the vulnerability and its potential impact on the organization is necessary to ensure effective management and mitigation. The CVE-2026-72795 vulnerability is a critical issue that requires prompt attention and action from affected organizations. By prioritizing patching, restricting access, and 7
Technical summary
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. This vulnerability allows attackers to request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization. The vulnerability has a CVSS score of 9.2 and is classified as CRITICAL. Organizations using SiYuan versions before v3.7.4 should prioritize patching to prevent unauthorized access to sensitive content.
Defensive priority
Organizations using SiYuan versions before v3.7.4 should prioritize patching to prevent unauthorized access to sensitive content.
Recommended defensive actions
- Patch SiYuan to version v3.7.4 or later
- Restrict access to published blocks containing embed queries
- Monitor for suspicious requests to published blocks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE description indicates that SiYuan versions before v3.7.4 fail to filter embedded block content by publish access, allowing attackers to read content from password-protected, hidden, or forbidden documents without authorization. However, the source detail is limited, and further verification is needed to confirm the vulnerability's impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72795 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72795
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72795 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72795
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h6w7-xxcf-w2mq
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-embed-block
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.