CVE-2026-72799: SiYuan before v3.7.4 Information Disclosure via Path Resolution
SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapping notebook names, folder hierarchies, and document titles, and resolving title paths to document IDs, including for documents marked hidden, password-protected, or publish-forbidden.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72799?
The severity of CVE-2026-72799 is rated as medium with a score of 5.8.
How do I fix CVE-2026-72799?
To fix CVE-2026-72799, upgrade SiYuan to version 3.7.4 or later.
What type of vulnerability is CVE-2026-72799?
CVE-2026-72799 is an information disclosure vulnerability affecting SiYuan.
Who is affected by CVE-2026-72799?
Users of SiYuan versions prior to v3.7.4 are affected by CVE-2026-72799.
What does CVE-2026-72799 exploit?
CVE-2026-72799 exploits the failure to enforce publish-access filters on specific path-resolution endpoints.