What is CVE-2026-73630?
SiYuan note-taking application prior to version 3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint. The endpoint, despite being intended for authenticated access, is reachable anonymously and leaks information about the file tree structure through its failure response messages. Immediate update to version 3.7.4 or above is required.
Azərbaycanca: SiYuan qeyd dəftəri tətbiqinin 3.7.4 versiyasından əvvəlki versiyalarında, /api/filetree/authFilePublishAccess API endpoint-ində məlumat sızması zəifliyi aşkar edilib. Bu endpoint yalnız CheckAuth ilə qeydiyyatdan keçsə də, anonim şəkildə əldə edilə bilir və cavab mesajları vasitəsilə məxfi fayl ağacı strukturu barədə məlumat sızdıra bilir. Təsirə məruz qalan sistemlərdə dərhal 3.7.4 və ya daha yuxarı versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which API endpoint of the SiYuan application was the CVE-2026-73630 vulnerability discovered?
In the /api/filetree/authFilePublishAccess endpoint.
What version is recommended to update to in order to fix this information disclosure issue?
Version 3.7.4 or above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.