SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and getBlockRelevantIDs endpoints enumerate workspace-wide block IDs without publish scoping, enabling attackers to discover valid block identifiers across publish boundaries and access content from hidden or password-protected documents.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 20:17
Updated : 2026-08-26 16:56
NVD link : CVE-2026-72800
Mitre link : CVE-2026-72800
CVE.ORG link : CVE-2026-72800
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
