PT-2026-72009 · Siyuan · Siyuan

·

CVE-2026-73048

·

Published

2026-08-14

·

Updated

2026-08-26

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description An information disclosure issue exists in the 'getRefIDsByFileAnnotationID' endpoint. The system returns block identifiers that cite PDF annotations without applying publish-access filtering. This allows attackers to extract block identifiers from restricted documents by providing annotation identifiers visible on published pages, thereby exposing citation relationships across password-protected and forbidden tiers.
Recommendations Update SiYuan to version 3.7.4 or later. As a temporary mitigation, restrict access to the 'getRefIDsByFileAnnotationID' endpoint.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73048

Affected Products

Siyuan