SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 14:16
Updated : 2026-08-26 17:05
NVD link : CVE-2026-68584
Mitre link : CVE-2026-68584
CVE.ORG link : CVE-2026-68584
JSON object : View
Products Affected
No product.
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
