PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73608 siyuan-note CVE debrief

The CVE-2026-73608 vulnerability affects SiYuan's development branch, specifically the /api/av/getAttributeViewSearchTarget endpoint. This endpoint lacks proper authorization checks, allowing an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, with primary records from Vulncheck and the NVD. The affected product or component is SiYuan's development branch, which is vulnerable to unauthorized data access due to a missing-authorization vulnerability. The likely operational impact is high, as an anonymous reader can retrieve sensitive data. The source-confidence limits are moderate, as the evidence is based on limited source detail. The review context is critical, as the vulnerability allows unauthorized data access.

Vendor
siyuan-note
Product
siyuan
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-26
Advisory published
2026-08-13
Advisory updated
2026-08-26

Who should care

SiYuan users and administrators, especially those using the development branch, should apply the patch (v3.7.4) to prevent unauthorized data access. Affected operator, platform, vulnerability-management, and security-team impact should be considered. The vulnerability affects SiYuan's development branch, and users should take immediate action to apply the patch. The impacted stakeholders include SiYuan users, administrators, and security teams who need to ensure the patch is applied to prevent unauthorized data access. Additionally, vulnerability management and security teams should review the affected endpoint and implement compensating controls to detect and prevent unauthorized access. The impacted platforms include SiYuan's development branch, and the vulnerability management teams should review the affected endpoint and implement compensating controls to detect and prevent unauthorized access. The security teams should also review the affected endpoint and implement compensating controls to detect and prevent unauthorized access. The affected systems should be reviewed and patched as soon as possible to prevent exploitation. The security teams should also monitor for suspicious queries to the affected endpoint and implement compensating controls, such as web application firewalls, to detect and prevent unauthorized access. The affected stakeholders should also inventory and review database identifiers exposed in published pages to prevent unauthorized data access. The affected stakeholders should also implement compensating controls, such as web application firewalls, to detect and prevent unauthorized access. The security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. The affected stakeholders should also verify and apply the vendor's patch (v3.7.4) to the affected SiYuan development branch. The security teams should also restrict access to the /api/av/getAttributeViewSearchTarget endpoint to prevent unauthorized data access. The affected stakeholders should also review compensating controls for exposed systems while remediation is scheduled and verified. The security teams should also (

Technical summary

The /api/av/getAttributeViewSearchTarget endpoint in SiYuan's development branch (introduced by commit 9b8e8956f) lacks proper authorization checks. This allows an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content, including rows that publish filters would otherwise withhold. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, with primary records from Vulncheck and the NVD. The affected product or component is SiYuan's development branch, which is vulnerable to unauthorized data access due to a missing-authorization vulnerability. The likely operational impact is high, as an anonymous reader can retrieve sensitive data. The source-confidence limits are moderate, as the evidence is based on limited source detail.

Defensive priority

Critical vulnerability in SiYuan's development branch, patched in v3.7.4, allowing unauthorized data access.

Recommended defensive actions

  • Verify and apply the vendor's patch (v3.7.4) to the affected SiYuan development branch.
  • Restrict access to the /api/av/getAttributeViewSearchTarget endpoint.
  • Monitor for suspicious queries to the affected endpoint.
  • Inventory and review database identifiers exposed in published pages.
  • Implement compensating controls, such as web application firewalls, to detect and prevent unauthorized access.

Evidence notes

The CVE-2026-73608 vulnerability affects SiYuan's development branch, specifically the /api/av/getAttributeViewSearchTarget endpoint. This endpoint lacks proper authorization checks, allowing an anonymous reader to query the endpoint with a database identifier and keyword to retrieve matching database row content. The vulnerability was patched in version 3.7.4. Evidence is based on limited source detail, with primary records from Vulncheck and the NVD.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73608 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73608

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73608 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73608

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.