What is CVE-2026-68587?
CVE-2026-68587 is an information disclosure vulnerability in SiYuan note-taking software versions before v3.7.3, affecting the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints. These endpoints return rendered block DOM without proper publish-access checks, potentially allowing anonymous readers or publish RoleReader tokens to access restricted content. Users should immediately upgrade to version v3.7.3 or later.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which endpoints in SiYuan are affected by the CVE-2026-68587 vulnerability?
The CVE-2026-68587 vulnerability affects the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints in SiYuan.
To which version should users upgrade to fix CVE-2026-68587?
To fix CVE-2026-68587, users should upgrade to version v3.7.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.