VYPR
Medium severity5.8OSV Advisory· Published Aug 3, 2026· Updated Aug 26, 2026

CVE-2026-68585

CVE-2026-68585

Description

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/siyuan-note/siyuan/kernelGo
< 0.0.0-20260721014951-ffde3b21eca40.0.0-20260721014951-ffde3b21eca4

Affected products

2
  • Siyuan Note/SiyuanOSV2 versions
    v3.7.3-beta.2, v3.7.3-beta.1, v3.7.0-rc.2, …+ 1 more
    • (no CPE)range: v3.7.3-beta.2, v3.7.3-beta.1, v3.7.0-rc.2, …
    • (no CPE)range: <3.7.3

Patches

Vulnerability mechanics

References

5

News mentions

1