SiYuan v3.6.2 contains an information disclosure vulnerability caused by improper authorization checks in the publish service's bookmark filtering, letting unauthenticated visitors access bookmarked blocks from password-protected documents, exploit requires access to the publish service.
id: CVE-2026-34453
info:
name: SiYuan <= v3.6.1 - Bookmark Data Disclosure
author: 0x_Akoko
s
...