DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-73606: CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint

CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint

Vulnerability ID: CVE-2026-73606
CVSS Score: 6.9
Published: 2026-10-01

An authorization bypass and information disclosure vulnerability in the SiYuan personal knowledge management system before version 3.7.4 allows unauthenticated attackers to query block relationship metadata from password-protected documents.

TL;DR

Unauthenticated API requests to /api/block/getRefIDs bypass password checks, leaking relationship hierarchies in SiYuan.


Technical Details

  • CWE ID: CWE-639
  • Attack Vector: Network (AV:N)
  • CVSS v4.0 Score: 6.9 (Medium)
  • EPSS Score: 0.00325 (Percentile: 23.20%)
  • Exploit Status: None (No public exploit)
  • CISA KEV Status: Not Listed
  • Affected Component: kernel/api/block.go (/api/block/getRefIDs)

Affected Systems

  • SiYuan personal knowledge management system
  • SiYuan: < 3.7.4 (Fixed in: 3.7.4)

Mitigation Strategies

  • Upgrade SiYuan kernel to v3.7.4 or later.
  • Disable anonymous publish mode if immediate upgrade is not feasible.
  • Enforce IP-level access controls to the SiYuan kernel api endpoint.

Remediation Steps:

  1. Verify the currently deployed SiYuan version.
  2. Update deployment configurations (Docker Compose, systemd, or native binaries) to reference v3.7.4 or later.
  3. Test endpoint response behavior by issuing unauthenticated POST requests to /api/block/getRefIDs to confirm password-protected paths return filtered results.

References


Read the full report for CVE-2026-73606 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)