PatchSiren cyber security CVE debrief
CVE-2026-73608 siyuan-note CVE debrief
The CVE-2026-73608 vulnerability affects SiYuan's development branch, specifically the /api/av/getAttributeViewSearchTarget endpoint. This endpoint lacks proper authorization checks, allowing an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, with primary records from Vulncheck and the NVD. The affected product or component is SiYuan's development branch, which is vulnerable to unauthorized data access due to a missing-authorization vulnerability. The likely operational impact is high, as an anonymous reader can retrieve sensitive data. The source-confidence limits are moderate, as the evidence is based on limited source detail. The review context is critical, as the vulnerability allows unauthorized data access.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-26
Who should care
SiYuan users and administrators, especially those using the development branch, should apply the patch (v3.7.4) to prevent unauthorized data access. Affected operator, platform, vulnerability-management, and security-team impact should be considered. The vulnerability affects SiYuan's development branch, and users should take immediate action to apply the patch. The impacted stakeholders include SiYuan users, administrators, and security teams who need to ensure the patch is applied to prevent unauthorized data access. Additionally, vulnerability management and security teams should review the affected endpoint and implement compensating controls to detect and prevent unauthorized access. The impacted platforms include SiYuan's development branch, and the vulnerability management teams should review the affected endpoint and implement compensating controls to detect and prevent unauthorized access. The security teams should also review the affected endpoint and implement compensating controls to detect and prevent unauthorized access. The affected systems should be reviewed and patched as soon as possible to prevent exploitation. The security teams should also monitor for suspicious queries to the affected endpoint and implement compensating controls, such as web application firewalls, to detect and prevent unauthorized access. The affected stakeholders should also inventory and review database identifiers exposed in published pages to prevent unauthorized data access. The affected stakeholders should also implement compensating controls, such as web application firewalls, to detect and prevent unauthorized access. The security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. The affected stakeholders should also verify and apply the vendor's patch (v3.7.4) to the affected SiYuan development branch. The security teams should also restrict access to the /api/av/getAttributeViewSearchTarget endpoint to prevent unauthorized data access. The affected stakeholders should also review compensating controls for exposed systems while remediation is scheduled and verified. The security teams should also (
Technical summary
The /api/av/getAttributeViewSearchTarget endpoint in SiYuan's development branch (introduced by commit 9b8e8956f) lacks proper authorization checks. This allows an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content, including rows that publish filters would otherwise withhold. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, with primary records from Vulncheck and the NVD. The affected product or component is SiYuan's development branch, which is vulnerable to unauthorized data access due to a missing-authorization vulnerability. The likely operational impact is high, as an anonymous reader can retrieve sensitive data. The source-confidence limits are moderate, as the evidence is based on limited source detail.
Defensive priority
Critical vulnerability in SiYuan's development branch, patched in v3.7.4, allowing unauthorized data access.
Recommended defensive actions
- Verify and apply the vendor's patch (v3.7.4) to the affected SiYuan development branch.
- Restrict access to the /api/av/getAttributeViewSearchTarget endpoint.
- Monitor for suspicious queries to the affected endpoint.
- Inventory and review database identifiers exposed in published pages.
- Implement compensating controls, such as web application firewalls, to detect and prevent unauthorized access.
Evidence notes
The CVE-2026-73608 vulnerability affects SiYuan's development branch, specifically the /api/av/getAttributeViewSearchTarget endpoint. This endpoint lacks proper authorization checks, allowing an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, with primary records from Vulncheck and the NVD.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73608 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73608
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73608 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73608
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqf-hhrq-7v45
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-authorization-bypass-via-getattributeviewsearchtarget
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.