CVE-2026-68585 Details
Description
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.
A metadata disclosure vulnerability exists in SiYuan versions prior to 3.7.3, specifically within the '/api/block/getBlockInfo' endpoint. This vulnerability allows the retrieval of document root metadata, including titles of publish-forbidden documents, without proper access checks. The endpoint can be accessed by anonymous users or those with a publish 'RoleReader' token, exposing information such as the document title, notebook, path, root ID, and icon for documents excluded from publishing by administrators.
Users are advised to update to SiYuan version 3.7.3 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pm3w-vxp9-ccwc | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pm3w-vxp9-ccwc | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/siyuan-before-metadata-disclosure-via-getblockinfo | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SiYuan | <= v3.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion