PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73610 siyuan-note CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T12:17:25.607Z and has not been modified since then. CVE-2026-73610 is an information disclosure vulnerability in SiYuan before v3.7.4. The local storage filter returns the administrator's entire storage map with only three keys sanitized, allowing unauthenticated attackers or publish readers to retrieve sensitive information by calling the getLocalStorage endpoint. This vulnerability can lead to exposure of closed-tab history, search keywords, private document identifiers, and expanded folder paths. Users of SiYuan before v3.7.4, administrators of affected systems, security teams responsible for patch management and vulnerability remediation, and operators of platforms hosting SiYuan installations should prioritize patching and review their exposure to this vulnerability.

Vendor
siyuan-note
Product
siyuan
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-26
Advisory published
2026-08-13
Advisory updated
2026-08-26

Who should care

Users of SiYuan before v3.7.4, administrators of affected systems, security teams responsible for patch management and vulnerability remediation, and operators of platforms hosting SiYuan installations should prioritize patching and review their exposure to this vulnerability. Security teams should also monitor for potential exploitation attempts and review access controls for the getLocalStorage endpoint.

Technical summary

CVE-2026-73610 is an information disclosure vulnerability in SiYuan before v3.7.4. The local storage filter returns the administrator's entire storage map with only three keys sanitized, allowing unauthenticated attackers or publish readers to retrieve sensitive information by calling the getLocalStorage endpoint. This vulnerability can lead to exposure of closed-tab history, search keywords, private document identifiers, and expanded folder paths.

Defensive priority

CVE-2026-73610 is rated MEDIUM with a CVSS score of 6.9; prioritize patching for exposed systems.

Recommended defensive actions

  • Inventory and assess exposure of SiYuan installations
  • Apply patches or upgrades to v3.7.4 or later
  • Monitor for unauthorized access to local storage
  • Restrict access to the getLocalStorage endpoint
  • Review and update security configurations
  • Verify patch deployment in QA and production environments
  • Check for indicators of compromise in existing logs

Evidence notes

The CVE-2026-73610 record indicates an information disclosure vulnerability in SiYuan before v3.7.4. Limited information is available about affected configurations and vendor response. The vulnerability allows unauthenticated attackers or publish readers to retrieve sensitive information by calling the getLocalStorage endpoint, which returns the administrator's entire storage map with only three keys sanitized. Defenders should verify the patch level of SiYuan installations, review local storage access controls, and monitor for unauthorized access to sensitive information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73610 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73610

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73610 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73610

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.