Sceawere
Vulnerability Detail
CVE-2026-72788UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiYuan UILayout Filter Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.8
- Creation Date
- 2h ago
- Vendor
- siyuan-note
- Product
- siyuan
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.8",
"pubDate": "2026-08-12T20:17:50.117Z",
"pubdate": "2026-08-12T20:17:50.117Z",
"executiveSummary": "SiYuan versions prior to v3.7.4 contain an information disclosure vulnerability residing within the UILayout filter. The vulnerability arises from an inadequate access control mechanism that fails to properly restrict administrator workspace state from publish readers. This flaw allows unauthenticated remote attackers to harvest sensitive administrative metadata by interacting directly with exposed application endpoints. The impact of successful exploitation includes the unauthorized retrieval of administrator open documents, internal search terms, sensitive notebook paths, and private asset locations, severely compromising confidentiality. The risk profile is critical due to the lack of authentication requirements and the exposure of sensitive internal system topology and user data. Exploitation requires network access to the target instance and does not necessitate prior authentication or specialized privileges, lowering the threshold for malicious actors to extract critical reconnaissance data from vulnerable deployments.",
"technicalDetails": "The vulnerability is localized within the UILayout filter component of SiYuan, which fails to correctly enforce authorization boundaries between administrative users and unauthenticated publish readers. The root cause stems from improper access control validation logic within the routing or filtering layer, allowing external clients to query restricted application states. Specifically, the vulnerable component exposes the getConf endpoint over the network without enforcing authentication or session validation checks.\nThe attack flow proceeds as follows: an unauthenticated attacker targets the exposed SiYuan instance over the network. By crafting an HTTP request directed at the getConf endpoint, the attacker bypasses all authentication hurdles normally associated with administrative oversight. Upon receiving the request, the UILayout filter improperly processes and returns the internal application configuration and workspace state. Consequently, the response payload delivers high-value intelligence, including the administrator's currently open documents, historical search terms, underlying notebook file paths, and private asset storage locations.\nThe affected product is SiYuan, specifically all versions prior to v3.7.4. The vulnerability is exploitable remotely over the network with zero authentication requirements and zero privilege requirements. Post-exploitation impact encompasses severe information disclosure, providing attackers with granular insights into the application structure, proprietary data locations, and active administrative workflows, which can be leveraged to mount secondary, more targeted attacks against the underlying infrastructure."
}