What is CVE-2026-73608?
SiYuan note-taking application's development branch contains a missing-authorization vulnerability in the `/api/av/getAttributeViewSearchTarget` endpoint. Although `CheckAuth` is registered, no further authorization checks are performed, potentially allowing authenticated users to access restricted data. Only the development environment is affected, and users should update to version v3.7.4 immediately.
Azərbaycanca: SiYuan qeyd dəftəri tətbiqinin inkişaf qolunda `/api/av/getAttributeViewSearchTarget` endpoint-də `CheckAuth` yoxlaması mövcud olsa da, əlavə icazə (authorization) yoxlanışı çatışmır. Bu boşluq autentifikasiya olunmuş istifadəçilərə məhdud məlumatlara icazəsiz giriş imkanı verə bilər, yalnız inkişaf mühitini təsirləndirir. İstifadəçilərə dərhal v3.7.4 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SiYuan
FAQ2
Which environment of the SiYuan application does CVE-2026-73608 affect?
This vulnerability only affects the development branch of SiYuan.
In which version of the SiYuan application is CVE-2026-73608 resolved?
Users are recommended to update to version v3.7.4 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.