GitHub Security Advisory (GHSA-f2rw-w22v-54vh)Vendor advisory
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-f2rw-w22v-54vh CVE-2026-72797
MEDIUM
SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus
Record summary
CVE-2026-72797 has a selected CVSS score of 6.9 (medium).
Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can enumerate all encrypted notebooks and their current unlock status, revealing sensitive notebook names and decryption state in memory.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.7.4 | affected |
| 3.7.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72797 VulnCheck Advisory: SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatusThird-party advisory
https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getencryptednotebookstatus