CVE-2026-68587: SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.3 - Compensating control
Restrict access to publish-disabled documents so that untrusted users/anonymous readers or RoleReader tokens cannot call getHeadingDeleteTransaction, getHeadingLevelTransaction, or getHeadingInsertTransaction to obtain rendered block DOM without publish-access checks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68587?
CVE-2026-68587 has a severity rating of 8.6, indicating a high risk.
How do I fix CVE-2026-68587?
To fix CVE-2026-68587, upgrade to SiYuan version 3.7.3 or later.
What type of vulnerability is CVE-2026-68587?
CVE-2026-68587 is an information disclosure vulnerability that affects several endpoints.
Who is affected by CVE-2026-68587?
CVE-2026-68587 affects users of SiYuan versions prior to 3.7.3, particularly those with anonymous or specific publish RoleReader tokens.
What endpoints are involved in CVE-2026-68587?
The vulnerable endpoints in CVE-2026-68587 include getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction.