What is CVE-2026-73606?
SiYuan versions before 3.7.4 contain an information disclosure vulnerability in the `/api/block/getRefIDs` endpoint, which fails to check password-protected document tiers. This allows unauthenticated readers to discover block identifiers referenced by protected documents. Upgrading to version 3.7.4 or later is recommended.
Azərbaycanca: SiYuan qeyd proqramının 3.7.4-dən əvvəlki versiyalarında `/api/block/getRefIDs` endpoint-də informasiya sızması zəifliyi aşkar edilib. Bu zəiflik, parolla qorunan sənədlərin istinad etdiyi blok identifikatorlarını autentifikasiya olunmamış oxuculara ifşa edir. Proqramı ən azı 3.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which SiYuan endpoint was the CVE-2026-73606 vulnerability discovered?
This information disclosure vulnerability was discovered in the `/api/block/getRefIDs` endpoint.
To remediate CVE-2026-73606, what is the minimum version of SiYuan that should be upgraded to?
Upgrading to version 3.7.4 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.