top of page
perceptive_background_267k.jpg

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInse…

Published:

3 August 2026 at 00:00:00

Alert date:

3 August 2026 at 17:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

SiYuan versions prior to v3.7.3 contain an information disclosure vulnerability affecting the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction API endpoints. These endpoints return rendered block DOM content without enforcing publish-access checks. As a result, anonymous users or those with publish RoleReader tokens can supply a heading block ID to read the full rendered content of documents that have publish access disabled. This bypass allows unauthorized access to restricted content that should not be publicly available. The vulnerability requires no authentication beyond a valid heading block ID, making it relatively easy to exploit. It affects the confidentiality of private or restricted notes and documents stored in SiYuan. Users are advised to upgrade to v3.7.3 or later to remediate this issue.

Technical details

Mitigation steps:

Affected products:

SiYuan

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page