CVE-2026-73607

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading identifiers for any document by supplying its identifier, even for documents forbidden to the requester.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-13 12:17

Updated : 2026-08-26 16:57


NVD link : CVE-2026-73607

Mitre link : CVE-2026-73607

CVE.ORG link : CVE-2026-73607


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization