GitHub Security Advisory (GHSA-5w7r-f4cg-rqq7)Vendor advisory
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5w7r-f4cg-rqq7 CVE-2026-72799
MEDIUM
SiYuan before v3.7.4 Information Disclosure via Path Resolution
Record summary
CVE-2026-72799 has a selected CVSS score of 6.9 (medium).
Description
SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated (anonymous) reader — or any publish reader token — can call these endpoints to enumerate the complete private document tree, mapping notebook names, folder hierarchies, and document titles, and resolving title paths to document IDs, including for documents marked hidden, password-protected, or publish-forbidden.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.7.4 | affected |
| 3.7.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72799 VulnCheck Advisory: SiYuan before v3.7.4 Information Disclosure via Path ResolutionThird-party advisory
https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-path-resolution