What is CVE-2026-73609?
SiYuan versions prior to v3.7.4 have an information disclosure vulnerability in the getBookmarkLabels endpoint, which returns all bookmark labels without publish-access filtering. This allows anonymous readers and publish-mode readers to obtain the complete bookmark vocabulary across the workspace. Users should update to version v3.7.4 or later.
Azərbaycanca: SiYuan platformasının v3.7.4-dən əvvəlki versiyalarında, getBookmarkLabels endpoint-ində informasiya sızması zəifliyi aşkar edilib. Bu zəiflik, anonim istifadəçilərə və publish rejimində oxuculara bütün iş sahəsi üzrə bookmark etiketlərini əldə etməyə imkan verir. İstifadəçilərə dərhal v3.7.4 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of SiYuan are affected by CVE-2026-73609?
This vulnerability affects SiYuan versions prior to v3.7.4.
What can an attacker obtain by exploiting CVE-2026-73609?
Anonymous users or readers in publish mode can obtain all bookmark labels across the entire workspace.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.