CVE-2026-72788: SiYuan before v3.7.4 Information Disclosure via UILayout Filter
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72788?
The severity of CVE-2026-72788 is classified as medium with a score of 5.8.
How do I fix CVE-2026-72788?
To fix CVE-2026-72788, update SiYuan to version 3.7.4 or later.
What type of vulnerability is represented by CVE-2026-72788?
CVE-2026-72788 is an information disclosure vulnerability.
Who is affected by CVE-2026-72788?
CVE-2026-72788 affects users of SiYuan versions prior to 3.7.4.
What can attackers do with CVE-2026-72788?
Attackers can exploit CVE-2026-72788 to retrieve the administrator's open documents and other sensitive information.