MEDIUM 6.9 NVD
CVE-2026-72790
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without autho
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-74pj-6g7r-j55c
- https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getnotebooki
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-74pj-6g7r-j55c
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.