What is CVE-2026-68585?
CVE-2026-68585 is a metadata disclosure vulnerability in SiYuan versions before v3.7.3, affecting the `/api/block/getBlockInfo` endpoint. It allows anonymous readers or users with a publish RoleReader token to retrieve metadata, including titles, of documents that are forbidden from publishing. Upgrading to SiYuan version 3.7.3 or later is recommended to fix this vulnerability.
Azərbaycanca: CVE-2026-68585, SiYuan proqramının 3.7.3-dən əvvəlki versiyalarında `/api/block/getBlockInfo` endpointində metadata sızması zəifliyidir. Bu zəiflik anonim istifadəçilərə və ya `publish RoleReader` tokeninə malik şəxslərə, nəşrə qadağa qoyulmuş sənədlərin başlıq kimi metadata məlumatlarını əldə etməyə imkan verir. Bu problemi aradan qaldırmaq üçün SiYuan proqramını 3.7.3 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by CVE-2026-68585?
This vulnerability affects SiYuan versions before v3.7.3.
How can I protect against CVE-2026-68585?
It is recommended to upgrade to SiYuan version 3.7.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.