SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing the operating-system username and installation layout.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 20:17
Updated : 2026-08-26 16:56
NVD link : CVE-2026-72802
Mitre link : CVE-2026-72802
CVE.ORG link : CVE-2026-72802
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
