PT-2026-67404 · Siyuan · Siyuan

·

CVE-2026-68587

·

Published

2026-08-03

·

Updated

2026-09-10

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.3
Description An information disclosure issue exists where the endpoints 'getHeadingDeleteTransaction', 'getHeadingLevelTransaction', and 'getHeadingInsertTransaction' return rendered block DOM without performing publish-access checks. This allows anonymous readers or users with publish RoleReader tokens to provide a heading block ID and read the full rendered content of documents that are disabled for publishing and should be restricted.
Recommendations Update to version 3.7.3 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68587
GHSA-69MH-GVH4-8GP7
GHSA-85XQ-27M5-59M9
GO-2026-6381

Affected Products

Siyuan