PatchSiren cyber security CVE debrief
CVE-2026-73606 siyuan-note CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:25.043Z and has not been modified since then. The NVD entry is currently Deferred. CVE-2026-73606 is an information disclosure vulnerability in SiYuan versions before v3.7.4. The vulnerability exists in the /api/block/getRefIDs endpoint, which fails to check password-protected document tiers. This allows unauthenticated attackers to discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password. The vulnerability has a CVSS score of 6.9 and is rated MEDIUM. Users of SiYuan versions before v3.7.4 should be aware of this vulnerability and take steps to mitigate it. Specifically, administrators of SiYuan installations should verify their version and apply the necessary patches or updates as soon as possible. Operators, security teams, and platform administrators should review affected scope and vendor guidance to ensure proper mitigation and monitoring of exposed systems. The CVE Program and NVD provide official records and assessments of this vulnerability.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-26
Who should care
Users of SiYuan versions before v3.7.4 should be aware of this vulnerability and take steps to mitigate it. Specifically, administrators of SiYuan installations should verify their version and apply the necessary patches or updates as soon as possible. Operators, security teams, and platform administrators should review affected scope and vendor guidance to ensure proper mitigation and monitoring of exposed systems.
Technical summary
CVE-2026-73606 is an information disclosure vulnerability in SiYuan versions before v3.7.4. The vulnerability exists in the /api/block/getRefIDs endpoint, which fails to check password-protected document tiers. This allows unauthenticated attackers to discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password. The vulnerability has a CVSS score of 6.9 and is rated MEDIUM.
Defensive priority
CVE-2026-73606 is rated MEDIUM with a CVSS score of 6.9. Unauthenticated attackers can exploit this vulnerability to disclose information via the /api/block/getRefIDs endpoint in SiYuan versions before v3.7.4.
Recommended defensive actions
- Inventory and verify affected SiYuan versions before v3.7.4.
- Restrict access to the /api/block/getRefIDs endpoint.
- Implement compensating controls to monitor and track access to sensitive document blocks.
- Apply vendor remediation when available.
- Monitor for unauthorized access attempts to document blocks.
Evidence notes
The CVE-2026-73606 record indicates that SiYuan versions before v3.7.4 have an information disclosure vulnerability. The /api/block/getRefIDs endpoint fails to check password-protected document tiers, allowing unauthenticated readers to discover block identifiers without entering the document password. Evidence is limited to CVE and NVD records. Defenders should verify affected SiYuan deployments, review official advisories, and monitor for unauthorized access attempts to document blocks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vg99-7gj7-2fr5
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getrefids
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.