VYPR
Medium severity5.8NVD Advisory· Published Aug 12, 2026· Updated Aug 26, 2026

CVE-2026-72803

CVE-2026-72803

Description

SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/siyuan-note/siyuan/kernelGo
< 0.0.0-20260724093256-229fdffd7e4a0.0.0-20260724093256-229fdffd7e4a

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

1