Vulnerability Description
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-v684-q882-jgmq
- https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-enc
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-v684-q882-jgmq
FAQ
What is CVE-2026-72789?
CVE-2026-72789 is a vulnerability with a CVSS score of 8.6 (HIGH). SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted do...
How severe is CVE-2026-72789?
CVE-2026-72789 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72789?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.