PT-2026-67403 · Siyuan · Siyuan

·

CVE-2026-68586

·

Published

2026-08-03

·

Updated

2026-09-10

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.3
Description Insufficient publish-access filters are applied to the content endpoints '/api/ref/getBacklinkDoc' and '/api/ref/getBackmentionDoc'. While backlink list endpoints correctly filter documents forbidden from being published, these specific content endpoints only require authentication via CheckAuth. This allows a reader in publish-mode, including anonymous users if Basic Auth is disabled, to directly access these endpoints using a forbidden document's ID. Consequently, an attacker can retrieve the rendered DOM content of the document and use it as a reference-existence oracle to determine if the document references a specific block.
Recommendations Update SiYuan to version 3.7.3 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68586
GHSA-2MMH-4RF8-7XG6
GHSA-36V8-MPJM-8J5R
GO-2026-6379

Affected Products

Siyuan