What is CVE-2026-73610?
This vulnerability in SiYuan before v3.7.4 exposes sensitive information via the local storage filter, returning the admin's entire storage map with only three keys sanitized. Unauthenticated attackers or publish readers can retrieve closed-tab history, search keywords, and private document identifiers. Immediate update to v3.7.4 or later is required.
Azərbaycanca: Bu boşluq SiYuan qeyd tətbiqinin v3.7.4-dən əvvəlki versiyalarında lokal storage-də məxfilik məlumatlarının sızmasına səbəb olur. Autentifikasiya olunmamış hücumçular və ya sadəcə nəşr oxucuları bağlanmış tab-ların tarixçəsi, axtarış açar sözləri və şəxsi sənəd identifikatorları kimi həssas məlumatları əldə edə bilər. Dərhal v3.7.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What kind of data does CVE-2026-73610 expose in the SiYuan note-taking application?
The vulnerability exposes sensitive information such as closed-tab history, search keywords, and private document identifiers via local storage.
Which version should be updated to in order to mitigate CVE-2026-73610?
Immediate update to SiYuan v3.7.4 or later is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.