PatchSiren cyber security CVE debrief
CVE-2026-73610 siyuan-note CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:25.607Z and has not been modified since then. CVE-2026-73610 is an information disclosure vulnerability in SiYuan before v3.7.4. The local storage filter returns the administrator's entire storage map with only three keys sanitized, allowing unauthenticated attackers or publish readers to retrieve sensitive information by calling the getLocalStorage endpoint. This vulnerability can lead to exposure of closed-tab history, search keywords, private document identifiers, and expanded folder paths. Users of SiYuan before v3.7.4, administrators of affected systems, security teams responsible for patch management and vulnerability remediation, and operators of platforms hosting SiYuan installations should prioritize patching and review their exposure to this vulnerability.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-26
Who should care
Users of SiYuan before v3.7.4, administrators of affected systems, security teams responsible for patch management and vulnerability remediation, and operators of platforms hosting SiYuan installations should prioritize patching and review their exposure to this vulnerability. Security teams should also monitor for potential exploitation attempts and review access controls for the getLocalStorage endpoint.
Technical summary
CVE-2026-73610 is an information disclosure vulnerability in SiYuan before v3.7.4. The local storage filter returns the administrator's entire storage map with only three keys sanitized, allowing unauthenticated attackers or publish readers to retrieve sensitive information by calling the getLocalStorage endpoint. This vulnerability can lead to exposure of closed-tab history, search keywords, private document identifiers, and expanded folder paths.
Defensive priority
CVE-2026-73610 is rated MEDIUM with a CVSS score of 6.9; prioritize patching for exposed systems.
Recommended defensive actions
- Inventory and assess exposure of SiYuan installations
- Apply patches or upgrades to v3.7.4 or later
- Monitor for unauthorized access to local storage
- Restrict access to the getLocalStorage endpoint
- Review and update security configurations
- Verify patch deployment in QA and production environments
- Check for indicators of compromise in existing logs
Evidence notes
The CVE-2026-73610 record indicates an information disclosure vulnerability in SiYuan before v3.7.4. Limited information is available about affected configurations and vendor response. The vulnerability allows unauthenticated attackers or publish readers to retrieve sensitive information by calling the getLocalStorage endpoint, which returns the administrator's entire storage map with only three keys sanitized. Defenders should verify the patch level of SiYuan installations, review local storage access controls, and monitor for unauthorized access to sensitive information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73610 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73610
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73610 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73610
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-xp3q-r38w-vgqm
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-local-storage
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.