CVE-2026-72798: SiYuan before v3.7.4 Information Disclosure via renderAttributeView
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4 - Compensating control
Ensure anonymous readers cannot access hidden or password-protected databases until SiYuan is upgraded, since renderAttributeView may fail to properly filter related-database content in versions before v3.7.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72798?
CVE-2026-72798 has a high severity rating of 8.6.
How do I fix CVE-2026-72798?
To fix CVE-2026-72798, upgrade to SiYuan version 3.7.4 or later.
What kind of information is disclosed in CVE-2026-72798?
CVE-2026-72798 allows anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases.
What versions of SiYuan are affected by CVE-2026-72798?
SiYuan versions prior to 3.7.4 are affected by CVE-2026-72798.
Can CVE-2026-72798 lead to data leaks?
Yes, CVE-2026-72798 can lead to unauthorized access to sensitive data from restricted databases.