DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-73609: CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint

CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint

Vulnerability ID: CVE-2026-73609
CVSS Score: 5.8
Published: 2026-10-01

An information disclosure vulnerability (CWE-862) in the SiYuan Note platform before version v3.7.4 allows anonymous or unprivileged readers to obtain a complete list of bookmark labels globally across all workspaces and notebooks by querying the /api/attr/getBookmarkLabels API endpoint.

TL;DR

Missing authorization checks on the /api/attr/getBookmarkLabels endpoint in SiYuan Note allow unauthenticated or unprivileged users to query and retrieve all bookmark labels across the entire workspace, exposing confidential project names, structures, and metadata.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862
  • Attack Vector: Network
  • CVSS v3.1: 5.8
  • CVSS v4.0: 6.9
  • EPSS Score: 0.00325 (0.33%)
  • Exploit Status: Conceptual Proof of Concept

Affected Systems

  • SiYuan Note
  • SiYuan: < v3.7.4 (Fixed in: v3.7.4)

Code Analysis

Commit: 251596f

Enforce publish access controls for getBookmarkLabels

Exploit Details

  • VulnCheck: Information disclosure advisory highlighting the getBookmarkLabels endpoint vulnerability.

Mitigation Strategies

  • Upgrade SiYuan Note to version v3.7.4 or later
  • Bind Siyuan Note server strictly to localhost loopback interface (127.0.0.1)
  • Restrict endpoint access using Nginx or other reverse proxies to filter path /api/attr/getBookmarkLabels

Remediation Steps:

  1. Identify the current running version of Siyuan Note.
  2. Download the updated version (v3.7.4 or later) from the official GitHub repository.
  3. Apply the update and restart the server.
  4. Validate the fix by attempting an unauthenticated POST request to /api/attr/getBookmarkLabels.

References


Read the full report for CVE-2026-73609 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)