


Perceptive Security
SOC/SIEM Consultancy

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInse…
Published:
2 August 2026 at 22:00:00
Alert date:
3 August 2026 at 15:06:10
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
SiYuan versions prior to v3.7.3 contain an information disclosure vulnerability affecting the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction API endpoints. These endpoints return rendered block DOM content without enforcing publish-access checks. As a result, anonymous users or those with publish RoleReader tokens can supply a heading block ID to read the full rendered content of documents that have publish access disabled. This bypass allows unauthorized access to restricted content that should not be publicly available. The vulnerability requires no authentication beyond a valid heading block ID, making it relatively easy to exploit. It affects the confidentiality of private or restricted notes and documents stored in SiYuan. Users are advised to upgrade to v3.7.3 or later to remediate this issue.
Technical details
Mitigation steps:
Affected products:
SiYuan
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-68587
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-69mh-gvh4-8gp7
https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getheading-transaction
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
