PT-2026-71237 · Siyuan · Siyuan

·

CVE-2026-72795

·

Published

2026-08-12

·

Updated

2026-09-10

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description An issue exists where the software fails to filter embedded block content based on publish access permissions. While the initial requested block is checked for authorization, blocks pulled in via embed queries (transclusion) are inlined into the returned DOM without any access checks. This allows an anonymous reader or a user with a publish reader token to read content from documents that are hidden, forbidden, or password-protected, provided they request a legitimately published block that contains an embed query matching those private documents.
API Endpoints:
  • '/api/block/getBlockDOMWithEmbed'
  • '/api/block/getBlockDOMsWithEmbed'
Vulnerable Parameters or Variables:
  • id
  • ids
Function Names:
  • resolveEmbedContentInBox()
Recommendations Update SiYuan to version 3.7.4 or later. As a temporary workaround, avoid publishing documents that contain embed queries spanning sensitive or password-protected areas of the workspace.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72795
GHSA-CJWM-9H7G-PCR9
GHSA-H6W7-XXCF-W2MQ
GO-2026-6425

Affected Products

Siyuan