CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint
Vulnerability ID: CVE-2026-73609
CVSS Score: 5.8
Published: 2026-10-01
An information disclosure vulnerability (CWE-862) in the SiYuan Note platform before version v3.7.4 allows anonymous or unprivileged readers to obtain a complete list of bookmark labels globally across all workspaces and notebooks by querying the /api/attr/getBookmarkLabels API endpoint.
TL;DR
Missing authorization checks on the /api/attr/getBookmarkLabels endpoint in SiYuan Note allow unauthenticated or unprivileged users to query and retrieve all bookmark labels across the entire workspace, exposing confidential project names, structures, and metadata.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862
- Attack Vector: Network
- CVSS v3.1: 5.8
- CVSS v4.0: 6.9
- EPSS Score: 0.00325 (0.33%)
- Exploit Status: Conceptual Proof of Concept
Affected Systems
- SiYuan Note
-
SiYuan: < v3.7.4 (Fixed in:
v3.7.4)
Code Analysis
Commit: 251596f
Enforce publish access controls for getBookmarkLabels
Exploit Details
- VulnCheck: Information disclosure advisory highlighting the getBookmarkLabels endpoint vulnerability.
Mitigation Strategies
- Upgrade SiYuan Note to version v3.7.4 or later
- Bind Siyuan Note server strictly to localhost loopback interface (127.0.0.1)
- Restrict endpoint access using Nginx or other reverse proxies to filter path /api/attr/getBookmarkLabels
Remediation Steps:
- Identify the current running version of Siyuan Note.
- Download the updated version (v3.7.4 or later) from the official GitHub repository.
- Apply the update and restart the server.
- Validate the fix by attempting an unauthenticated POST request to /api/attr/getBookmarkLabels.
References
Read the full report for CVE-2026-73609 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)