CVE-2026-72803: SiYuan before v3.7.4 Information Disclosure via getBlockAttrs
SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72803?
The severity of CVE-2026-72803 is classified as medium with a score of 5.8.
How do I fix CVE-2026-72803?
To fix CVE-2026-72803, upgrade to SiYuan version 3.7.4 or later where the vulnerability is patched.
What type of vulnerability is CVE-2026-72803?
CVE-2026-72803 is an information disclosure vulnerability affecting SiYuan.
What can attackers access through CVE-2026-72803?
Attackers can retrieve block attributes such as names, aliases, memos, and custom fields from protected documents.
Which versions of SiYuan are affected by CVE-2026-72803?
SiYuan versions before 3.7.4 are affected by CVE-2026-72803.