SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan v3.7.4之前版本存在授权问题漏洞,该漏洞源于getBookmarkLabels端点未进行发布访问过滤,返回工作空间中所有书签标签,导致匿名读者和发布模式读者可获取完整书签词汇,泄露不可访问文档中的主题和组织信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
affected |
3.7.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73608 | 8.6 HIGH | SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget |
| CVE-2026-73606 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getRefIDs |
| CVE-2026-73610 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via Local Storage |
| CVE-2026-73607 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getOutlineStorage |
| CVE-2026-73605 | 5.8 MEDIUM | SiYuan before v3.7.4 Path Traversal via getUniqueFilename |
No comments yet