GitHub Security Advisory (GHSA-xp3q-r38w-vgqm)Vendor advisory
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-xp3q-r38w-vgqm CVE-2026-73610
MEDIUM
SiYuan before v3.7.4 Information Disclosure via Local Storage
Record summary
CVE-2026-73610 has a selected CVSS score of 6.9 (medium).
Description
SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map with only three keys sanitized. Unauthenticated attackers or publish readers can retrieve closed-tab history, search keywords, private document identifiers, and expanded folder paths by calling the getLocalStorage endpoint.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.7.4 | affected |
| 3.7.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73610 VulnCheck Advisory: SiYuan before v3.7.4 Information Disclosure via Local StorageThird-party advisory
https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-local-storage