SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 14:16
Updated : 2026-08-26 17:06
NVD link : CVE-2026-68587
Mitre link : CVE-2026-68587
CVE.ORG link : CVE-2026-68587
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
