CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure
Vulnerability ID: CVE-2026-73607
CVSS Score: 5.8
Published: 2026-10-01
An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.
TL;DR
A Broken Object Level Authorization (BOLA) vulnerability in SiYuan prior to v3.7.4 allows authenticated users to extract document outlines and structural metadata of unauthorized notes via the /api/storage/getOutlineStorage API endpoint.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862 (Missing Authorization)
- Attack Vector: Network (AV:N)
- CVSS v3.1 / v4.0: 5.8 (Medium) / 6.9 (Medium)
- EPSS Score: 0.00325 (Percentile: 23.20%)
- Impact: Information Disclosure (Confidentiality: Low)
- Exploit Status: PoC Available / No Active Exploitation
- KEV Status: Not Listed
Affected Systems
- SiYuan Personal Knowledge Management System
-
SiYuan: >= 0, < 3.7.4 (Fixed in:
3.7.4)
Mitigation Strategies
- Upgrade SiYuan to v3.7.4 or later
- Implement network-level segmentation to restrict API access
- Restrict user creation and guest access on server-mode instances
Remediation Steps:
- Verify the currently running version of the SiYuan kernel by inspecting the application logs or interface settings.
- Download the latest stable release (v3.8.0 or newer) from the official repository.
- Replace the old executable or container image with the updated version.
- Restart the SiYuan service and monitor authentication logs for standard API requests.
References
- GitHub Security Advisory (GHSA-53fp-9jmv-227g)
- VulnCheck Advisory
- CVE Record
- Official Patch Release Tag (v3.8.0)
Read the full report for CVE-2026-73607 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)