CVE-2026-73609

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-13 12:17

Updated : 2026-08-26 16:57


NVD link : CVE-2026-73609

Mitre link : CVE-2026-73609

CVE.ORG link : CVE-2026-73609


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization