Sceawere

Vulnerability Detail

CVE-2026-72799UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
2h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapping notebook names, folder hierarchies, and document titles, and resolving title paths to document IDs, including for documents marked hidden, password-protected, or publish-forbidden.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-08-12T20:17:51.690Z",
  "pubdate": "2026-08-12T20:17:51.690Z",
  "executiveSummary": "An information disclosure vulnerability has been identified in SiYuan <=v3.7.2 (before v3.7.4). The vulnerability involves the failure to enforce publish-access filters across five specific filetree path-resolution endpoints, specifically getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath.\nThis security flaw allows unauthenticated anonymous readers or users possessing any publish reader token to bypass intended access controls when publish mode is active and Publish.Auth.Enable is set to false.\nSuccessful exploitation enables unauthorized actors to completely enumerate the private document tree of the affected SiYuan instance. Attackers can map notebook names, folder hierarchies, and document titles, as well as resolve title paths to explicit document IDs.\nCrucially, this enumeration scope includes sensitive documents explicitly marked as hidden, password-protected, or publish-forbidden, posing severe risks to confidentiality and data privacy.\nThe attack vector requires network access to the vulnerable SiYuan instance with no prior authentication or privilege requirements under the specified publish mode configurations.",
  "technicalDetails": "The root cause of this vulnerability lies in inadequate access control enforcement and missing authorization checks within the application routing and handler logic for specific filetree path-resolution endpoints.\nThe affected vulnerable components comprise five distinct backend functions: getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath.\nThe affected software versions include SiYuan <=v3.7.2, with the issue patched prior to v3.7.4.\nThe vulnerability is exposed over network interfaces where the application operates in publish mode with Publish.Auth.Enable configured as false.\nExploitation requires zero authentication or privilege requirements. An unauthenticated attacker or an entity holding any valid publish reader token can directly interact with the vulnerable endpoints.\nThe attack flow proceeds as follows: First, the threat actor identifies a target SiYuan instance running an affected version with the vulnerable publish mode configuration. Second, the attacker sends crafted HTTP requests directly to one or more of the five vulnerable filetree path-resolution endpoints.\nBecause the backend handlers fail to validate the publish-access filters and authorization boundaries against the requesting context, the application processes the requests without restriction.\nThe application subsequently returns detailed structural data corresponding to the private document tree.\nThe payload behavior and resulting data exposure include notebook identifiers, hierarchical folder structures, document titles, and the capability to map human-readable title paths directly to internal document IDs.\nPost-exploitation impact encompasses total compromise of the document hierarchy metadata. Attackers can harvest internal identifiers for documents that were intentionally restricted, hidden, password-protected, or marked as publish-forbidden, facilitating subsequent targeted access attempts or further data leakage."
}
CVE-2026-72799: SiYuan Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.8) - Sceawere