Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72797— SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus

CVSS 5.8 · Medium EPSS 0.24% · P15

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 2

VendorProductVersion RangeStatus
siyuan-notesiyuan< 3.7.4affected
3.7.4unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-72797

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus
Source: CVE Program / CVE List V5
Vulnerability Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can enumerate all encrypted notebooks and their current unlock status, revealing sensitive notebook names and decryption state in memory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
SiYuan 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.4之前版本存在授权问题漏洞,该漏洞源于getEncryptedNotebookStatus端点未进行发布访问过滤,可能导致匿名读者和发布模式账户枚举所有加密笔记本及其解锁状态,泄露敏感笔记本名称和解密状态。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
siyuan-notesiyuan 0 ~ 3.7.4 -

II. Public POCs for CVE-2026-72797

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72797

登录查看更多情报信息。

Vendor Advisories for CVE-2026-72797 (2)

Same Patch Batch · siyuan-note · 2026-08-12 · 22 CVEs total

CVE-2026-727948.6 HIGHsiyuan before v3.7.4 Session Cookie Key Disclosure via getConf
CVE-2026-727938.6 HIGHSiYuan before v3.7.4 Information Disclosure via /api/system/getConf
CVE-2026-728048.6 HIGHSiYuan before v3.7.4 Authentication Bypass via Graph Endpoints
CVE-2026-727898.6 HIGHSiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks
CVE-2026-727988.6 HIGHSiYuan before v3.7.4 Information Disclosure via renderAttributeView
CVE-2026-727958.6 HIGHSiYuan before v3.7.4 Information Disclosure via Embed Block
CVE-2026-728098.0 HIGHSiYuan before v3.7.4 Authentication Bypass via Localhost Trust
CVE-2026-728078.0 HIGHSiYuan before v3.7.4 SQL Injection via queryBlocks template
CVE-2026-728017.5 HIGHSiYuan before v3.7.4 Information Disclosure via Encryption Key Material
CVE-2026-727905.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via getNotebookInfo
CVE-2026-728035.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via getBlockAttrs
CVE-2026-727965.8 MEDIUMSiYuan before v3.7.4 Access Control Bypass via Static Routes
CVE-2026-728085.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via getFileAnnotation
CVE-2026-728055.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via Block Endpoints
CVE-2026-727885.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via UILayout Filter
CVE-2026-727915.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via getAttributeViewFieldViews
CVE-2026-727925.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via Tag API
CVE-2026-727995.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via Path Resolution
CVE-2026-728065.8 MEDIUMSiYuan before v3.7.4 Authentication Bypass via Attribute View
CVE-2026-728005.8 MEDIUMSiYuan before v3.7.4 Information Disclosure via Unfiltered API

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72797

No comments yet


Leave a comment