SiYuan bug can expose secrets

Published September 3, 2026 CVE-2026-72804

The flaw affects SiYuan before v3.7.4 and has a security flaw.

Severity
HighCVSS 3.1 · 8.6
Fix
Fixed in 0.0.0-20260724091654-82e9ded423e4Fix recorded on Aug 26, 2026
Affected versions
before 0.0.0-20260724091654-82e9ded423e4
Weakness
CWE-200Exposure of Sensitive Information
Exploit likelihood
0.26% in 30 daysEPSS, higher than 17% of known flaws
Affects
SiYuan

What to do

Check whether the installed SiYuan version is older than v3.7.4.

Update SiYuan to v3.7.4 or newer. Then verify the installed version.

Technical details

The source identifies SiYuan as the affected product. Affected ranges: before v3.7.4. Fixed versions: v3.7.4.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact None No data tampering
  • Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Open in FIRST.org calculator