GitHub Security Advisory (GHSA-53fp-9jmv-227g)Vendor advisory
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g CVE-2026-73607
MEDIUM
SiYuan before v3.7.4 Information Disclosure via getOutlineStorage
Record summary
CVE-2026-73607 has a selected CVSS score of 6.9 (medium).
Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading identifiers for any document by supplying its identifier, even for documents forbidden to the requester.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.7.4 | affected |
| 3.7.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73607 VulnCheck Advisory: SiYuan before v3.7.4 Information Disclosure via getOutlineStorageThird-party advisory
https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getoutlinestorage