CVE-2026-72797: SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can enumerate all encrypted notebooks and their current unlock status, revealing sensitive notebook names and decryption state in memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4 - Compensating control
Restrict access to the SiYuan getEncryptedNotebookStatus endpoint so anonymous readers and publish-mode accounts cannot enumerate encrypted notebooks and their current unlock/lock state.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72797?
The severity of CVE-2026-72797 is medium, with a score of 5.8.
What kind of vulnerability is CVE-2026-72797?
CVE-2026-72797 is an information disclosure vulnerability.
How do I fix CVE-2026-72797?
To fix CVE-2026-72797, upgrade to SiYuan version 3.7.4 or later.
What does CVE-2026-72797 affect?
CVE-2026-72797 affects SiYuan versions prior to 3.7.4.
What information can be disclosed due to CVE-2026-72797?
CVE-2026-72797 can disclose encrypted notebook identifiers, names, and lock states.