CVE-2026-73607: SiYuan before v3.7.4 Information Disclosure via getOutlineStorage
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading identifiers for any document by supplying its identifier, even for documents forbidden to the requester.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4 - Compensating control
Restrict access to the /api/storage/getOutlineStorage endpoint (e.g., via network/WAF/ACL) until the SiYuan upgrade to v3.7.4 is applied, since the endpoint performs no authorization checks in versions before v3.7.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73607?
The severity of CVE-2026-73607 is medium with a CVSS score of 5.8.
How do I fix CVE-2026-73607?
To fix CVE-2026-73607, upgrade to SiYuan version 3.7.4 or later.
What type of vulnerability is CVE-2026-73607?
CVE-2026-73607 is an information disclosure vulnerability.
What can attackers access through CVE-2026-73607?
Attackers can access the outline state and heading identifiers for any document without authorization.
In which version of SiYuan was CVE-2026-73607 fixed?
CVE-2026-73607 was fixed in SiYuan version 3.7.4.