


Perceptive Security
SOC/SIEM Consultancy

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/g…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 15:06:10
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
SiYuan versions before v3.7.3 contain a vulnerability where publish-access filters are not applied to the getBacklinkDoc and getBackmentionDoc content endpoints. While backlink list endpoints correctly filter publish-forbidden documents, the content endpoints are only gated by CheckAuth, leaving them accessible to publish-mode readers. An anonymous reader, when publish Basic Auth is disabled, can directly call these endpoints using a publish-forbidden document's ID to retrieve rendered DOM content. This also enables a reference-existence oracle attack, allowing the attacker to determine whether a document references a specific block. The flaw represents an improper access control issue in SiYuan's publish mode functionality. The vulnerability has been assigned CVE-2026-68586 and is patched in v3.7.3.
Technical details
Mitigation steps:
Affected products:
SiYuan before v3.7.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-68586
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-36v8-mpjm-8j5r
https://www.vulncheck.com/advisories/siyuan-before-content-disclosure-via-getbacklinkdoc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
