Description
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
Published: 2026-08-12
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthenticated disclosure of confidential document content via the getBlockDOMWithEmbed and getBlockDOMsWithEmbed API endpoints. Because embedded blocks are not filtered by publish access, an attacker can fetch blocks that reference password‑protected, hidden or forbidden documents and obtain their raw text. This results in a confidentiality breach where sensitive data becomes accessible to anyone who can send requests to the exposed API.

Affected Systems

SiYuan applications prior to version 3.7.4 are impacted. Users running any earlier release of the Siyuan note editor should assume their instance is vulnerable. The problem exists in all distributions of the product bundled with the published endpoints, regardless of deployment environment.

Risk and Exploitability

The CVSS score of 9.2 classifies the flaw as critical. The EPSS score is not available, but the lack of exploitation markers and its presence in public advisories suggest a high likelihood of abuse. The attack can be carried out remotely by constructing a request to the exposed API endpoints; authentication is not required, just knowledge of the block identifiers. Because the vulnerability is enumerated in a public advisory and is not listed in CISA KEV, it remains a significant risk that an attacker can read private data from any published document that contains embedded block references.

Generated by OpenCVE AI on August 12, 2026 at 23:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 3.7.4 or later to apply the vendor patch that filters embedded block content by publish access.
  • Restrict or disable the getBlockDOMWithEmbed and getBlockDOMsWithEmbed API routes on servers that do not need to expose embedded block content.
  • Re‑configure document permission settings to limit publishing of blocks that could expose sensitive content, and audit documents that might contain embedded block references.

Generated by OpenCVE AI on August 12, 2026 at 23:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
Title SiYuan before v3.7.4 Information Disclosure via Embed Block
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-12T20:55:07.491Z

Reserved: 2026-08-10T15:11:03.190Z

Link: CVE-2026-72795

cve-icon Vulnrichment

Updated: 2026-08-12T20:42:34.696Z

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:51.137

Modified: 2026-08-12T21:17:40.073

Link: CVE-2026-72795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:15:03Z

Weaknesses