CVE-2026-72795: SiYuan before v3.7.4 Information Disclosure via Embed Block
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72795?
The severity of CVE-2026-72795 is rated as high with a score of 8.6.
How do I fix CVE-2026-72795?
To fix CVE-2026-72795, upgrade SiYuan to version 3.7.4 or later.
What impact does CVE-2026-72795 have on data security?
CVE-2026-72795 allows attackers to access content from password-protected and hidden documents, posing a risk of information disclosure.
Which versions of SiYuan are affected by CVE-2026-72795?
SiYuan versions prior to 3.7.4 are affected by CVE-2026-72795.
Can CVE-2026-72795 be exploited without authentication?
Yes, CVE-2026-72795 can be exploited without authentication, allowing unauthorized access to sensitive content.