What is CVE-2026-73607?
SiYuan versions before v3.7.4 have an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint due to missing authorization checks. Attackers can retrieve outline data, including heading identifiers, for any document by providing its identifier. Immediate update to v3.7.4 or later is required, along with restricting network access.
Azərbaycanca: SiYuan v3.7.4-dən əvvəlki versiyalarda `/api/storage/getOutlineStorage` endpoint-də avtorizasiya yoxlanışı olmadığı üçün informasiya sızması zəifliyi mövcuddur. Bu, icazəsiz istifadəçilərə sənəd identifikatorunu bilməklə başlıq identifikatorları kimi məxfi outline məlumatlarını əldə etməyə imkan verir. Dərhal v3.7.4 və ya daha yeni versiyaya yenilənməli və şəbəkə girişi məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of SiYuan are affected by the information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint?
This vulnerability exists in SiYuan versions before v3.7.4.
What kind of data can an attacker retrieve by exploiting this vulnerability?
Unauthorized users can retrieve confidential outline data, including heading identifiers, by providing the document identifier.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.