CVE-2026-72790: SiYuan before v3.7.4 Information Disclosure via getNotebookInfo
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72790?
The severity of CVE-2026-72790 is classified as medium with a score of 5.8.
How do I fix CVE-2026-72790?
To fix CVE-2026-72790, upgrade SiYuan to version 3.7.4 or later, which addresses the vulnerability.
What type of vulnerability is CVE-2026-72790?
CVE-2026-72790 is an information disclosure vulnerability found in the /api/notebook/getNotebookInfo endpoint.
What can attackers do with CVE-2026-72790?
Attackers exploiting CVE-2026-72790 can read notebook names, document counts, sizes, and timestamps of non-published notebooks.
Which version of SiYuan is affected by CVE-2026-72790?
SiYuan versions before 3.7.4 are affected by CVE-2026-72790.