CVE-2026-72790

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 20:17

Updated : 2026-08-26 16:56


NVD link : CVE-2026-72790

Mitre link : CVE-2026-72790

CVE.ORG link : CVE-2026-72790


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization