Vulnerability Description
SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-qvq9-hq6p-v378
- https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-ge
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-qvq9-hq6p-v378
FAQ
What is CVE-2026-72803?
CVE-2026-72803 is a vulnerability with a CVSS score of 5.8 (MEDIUM). SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and ...
How severe is CVE-2026-72803?
CVE-2026-72803 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72803?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.