What is CVE-2026-73048?
SiYuan note-taking software versions prior to 3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint, which returns block identifiers referencing PDF annotations without proper publish-access filtering. Attackers can extract block identifiers from restricted documents by exploiting this flaw. Upgrading to version 3.7.4 or later is required to mitigate the risk.
Azərbaycanca: SiYuan qeydiyyat proqramının 3.7.4-dən əvvəlki versiyalarında 'getRefIDsByFileAnnotationID' API-sində informasiya sızması zəifliyi aşkar edilib. Bu zəiflik, məhdud girişli sənədlərdəki PDF annotasiyalarına istinad edən blok identifikatorlarının filtrasiya olunmadan qaytarılmasına səbəb olur. Təhlükəsizlik üçün proqramı ən azı 3.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by the CVE-2026-73048 vulnerability?
This information disclosure vulnerability affects SiYuan note-taking software versions prior to 3.7.4.
How can users mitigate the risk of CVE-2026-73048?
To mitigate the risk, users should upgrade SiYuan to version 3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.