CVE-2026-59853

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths, notebook, document, and block IDs, and search and replace keywords for unpublished documents. This issue is fixed in versions 3.7.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-09 23:17

Updated : 2026-07-10 15:49


NVD link : CVE-2026-59853

Mitre link : CVE-2026-59853

CVE.ORG link : CVE-2026-59853


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization