GitHub Security Advisory (GHSA-6mcf-g667-w3qv)Vendor advisory
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6mcf-g667-w3qv CVE-2026-72806
MEDIUM
SiYuan before v3.7.4 Authentication Bypass via Attribute View
Record summary
CVE-2026-72806 has a selected CVSS score of 6.9 (medium).
Description
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows including titles, block IDs, and column values by calling renderAttributeView without supplying the required password.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.7.4 | affected |
| 3.7.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72806 VulnCheck Advisory: SiYuan before v3.7.4 Authentication Bypass via Attribute ViewThird-party advisory
https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-attribute-view