SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.4之前版本存在授权问题漏洞,该漏洞源于八个发布模式面向读者的端点存在授权错误,使用可见性列表而非禁用列表过滤结果,导致匿名访问者可通过访问搜索、反向链接、资源内容、保存条件、最近文档、图形和标签等端点,发现并读取被明确标记为禁止发布的文档内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
affected |
3.7.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74902 | 8.6 HIGH | SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload |
| CVE-2026-74904 | 7.5 HIGH | SiYuan before v3.7.4 Missing Authorization via block API |
| CVE-2026-74905 | 7.1 HIGH | SiYuan before v3.7.4 SSRF via IPv6 Transition Address Bypass |
| CVE-2026-74903 | 4.3 MEDIUM | SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM |
No comments yet