MEDIUM 6.9 NVD
CVE-2026-72803
SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attribut
SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-qvq9-hq6p-v378
- https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getblockattr
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.