SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths, notebook, document, and block IDs, and search and replace keywords for unpublished documents. This issue is fixed in versions 3.7.1.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-09 23:17
Updated : 2026-07-10 15:49
NVD link : CVE-2026-59853
Mitre link : CVE-2026-59853
CVE.ORG link : CVE-2026-59853
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
