CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint
Vulnerability ID: CVE-2026-73606
CVSS Score: 6.9
Published: 2026-10-01
An authorization bypass and information disclosure vulnerability in the SiYuan personal knowledge management system before version 3.7.4 allows unauthenticated attackers to query block relationship metadata from password-protected documents.
TL;DR
Unauthenticated API requests to /api/block/getRefIDs bypass password checks, leaking relationship hierarchies in SiYuan.
Technical Details
- CWE ID: CWE-639
- Attack Vector: Network (AV:N)
- CVSS v4.0 Score: 6.9 (Medium)
- EPSS Score: 0.00325 (Percentile: 23.20%)
- Exploit Status: None (No public exploit)
- CISA KEV Status: Not Listed
- Affected Component: kernel/api/block.go (/api/block/getRefIDs)
Affected Systems
- SiYuan personal knowledge management system
-
SiYuan: < 3.7.4 (Fixed in:
3.7.4)
Mitigation Strategies
- Upgrade SiYuan kernel to v3.7.4 or later.
- Disable anonymous publish mode if immediate upgrade is not feasible.
- Enforce IP-level access controls to the SiYuan kernel api endpoint.
Remediation Steps:
- Verify the currently deployed SiYuan version.
- Update deployment configurations (Docker Compose, systemd, or native binaries) to reference v3.7.4 or later.
- Test endpoint response behavior by issuing unauthenticated POST requests to /api/block/getRefIDs to confirm password-protected paths return filtered results.
References
- Official GitHub Security Advisory
- VulnCheck Security Advisory
- NIST National Vulnerability Database (NVD)
- CVE.org Record
- SiYuan Repository
- SiYuan v3.8.0 Release Notes
Read the full report for CVE-2026-73606 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)