Description
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted.
Published: 2026-08-03
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan versions before 3.7.3 expose the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints to return rendered block DOM without performing publish‑access checks. This flaw allows anyone with an anonymous or RoleReader token to supply a heading block ID and retrieve the fully rendered content of documents that should be publish‑disabled. The vulnerability constitutes a critical information disclosure, enabling attackers to read confidential material that was intended to remain restricted.

Affected Systems

All releases of the Siyuan‑note Siyuan product with a version number lower than 3.7.3 are affected. Administrators should confirm that their deployment is at least v3.7.3, as earlier releases contain the flaw.

Risk and Exploitability

The CVSS score of 9.2 classifies the issue as critical, and the absence of an authentication requirement makes exploitation trivial for anyone who can reach the API. Although the EPSS score is not published, the high severity and the presence of a security advisory indicate a substantial risk. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits exist yet, but the exposed endpoints provide a broad attack surface across any network that can connect to the Siyuan instance.

Generated by OpenCVE AI on August 4, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Siyuan v3.7.3 or later to remediate the missing publish‑access check in the vulnerable endpoints.
  • Reconfigure the server to disallow anonymous or RoleReader tokens from accessing getHeading*Transaction endpoints; if possible, remove or restrict these tokens for public interfaces.
  • Implement network or firewall rules that limit access to the API from untrusted IP ranges until the software patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared B3log
B3log siyuan
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Mon, 03 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted.
Title SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:51:08.876Z

Reserved: 2026-07-31T11:56:29.760Z

Link: CVE-2026-68587

cve-icon Vulnrichment

Updated: 2026-08-03T15:25:49.583Z

cve-icon NVD

Status : Received

Published: 2026-08-03T14:16:28.397

Modified: 2026-08-03T16:16:31.287

Link: CVE-2026-68587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:30:07Z

Weaknesses