PatchSiren cyber security CVE debrief
CVE-2026-72805 siyuan-note CVE debrief
SiYuan versions before v3.7.4 have a vulnerability that allows disclosure of protected document content and metadata. The vulnerability exists in the getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, which fail to enforce publish-access checks. This allows anonymous readers or publish RoleReader accounts to retrieve document titles, ancestor block content snippets, reference text, and path metadata for publish-forbidden or password-protected documents by supplying block IDs.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-26
Who should care
Users of SiYuan versions before v3.7.4, administrators of affected systems, security teams responsible for monitoring and protecting sensitive information, and operators who manage or interact with documents in SiYuan. These stakeholders should be aware of the potential for information disclosure and take steps to protect sensitive documents and metadata. This includes reviewing and updating SiYuan to version v3.7.4 or later, restricting access to sensitive documents and metadata, and monitoring for suspicious activity on the affected endpoints. Additionally, security teams should prioritize the protection of sensitive information and consider the potential impact of this vulnerability on their organization's security posture. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Furthermore, operators who manage or interact with documents in SiYuan should be cautious when supplying block IDs and ensure that they have the necessary permissions to access the requested documents. By taking these steps, stakeholders can help mitigate the risk of information disclosure and protect sensitive information. The CVE record was published on 2026-08-12T20:17:52.527Z and has not been modified since then, indicating a consistent level of risk that should be addressed through proactive security measures. Therefore, it is essential for stakeholders to remain vigilant and take proactive steps to protect their systems and data. This may involve reviewing and updating security policies, procedures, and controls to ensure that they are effective in mitigating the risk of information disclosure. By doing so, stakeholders can help prevent potential security breaches and protect sensitive information from unauthorized access. Overall, the whoShouldCare field is critical in highlighting the importance of proactive security measures in mitigating the risk of information disclosure and protecting sensitive information. By prioritizing the protection of sensitive information and taking proactive steps to address the vulnerability,
Technical summary
The vulnerability exists in the getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints of SiYuan versions before v3.7.4. These endpoints fail to enforce publish-access checks, allowing anonymous readers or publish RoleReader accounts to retrieve document titles, ancestor block content snippets, reference text, and path metadata for publish-forbidden or password-protected documents by supplying block IDs.
Defensive priority
Medium priority due to the potential for information disclosure.
Recommended defensive actions
- Review and update SiYuan to version v3.7.4 or later
- Restrict access to sensitive documents and metadata
- Monitor for suspicious activity on the affected endpoints
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability was reported by an unknown source and has been documented in the CVE Program record and the NVD vulnerability detail page. However, there is limited information available about the vulnerability, and further investigation is needed to fully understand its impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72805 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72805
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72805 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72805
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-67x2-mq63-v9vm
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-block-endpoints
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.