Description
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type.
Published: 2026-08-12
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan versions prior to 3.7.4 do not enforce proper filtering of related‑database content when rendering attribute views, which allows unauthenticated viewers to access the contents of Relation and Rollup cells that belong to hidden or password‑protected databases. As a result, sensitive data can be disclosed through published databases that reference restricted ones or by bypassing row‑level filtering when the first column is a non‑block type.

Affected Systems

SiYuan Note (siyuan) products running any version earlier than 3.7.4 are affected. The vulnerability manifests when a database is published with relationships pointing to hidden or protected databases, enabling anonymous readers to retrieve restricted cell contents through the renderAttributeView functionality.

Risk and Exploitability

The CVSS score of 9.2 classifies this flaw as critical, and the KEV listing is not present, indicating no widespread exploitation has been recorded yet. The EPSS score is unavailable, so the exact exploit probability cannot be quantified. The likely attack vector is remote, as an attacker only needs network or web access to the running instance to request a published database and trigger the vulnerable renderAttributeView process. No authentication or privileged access is required, so anyone who can reach the service is potentially able to exfiltrate sensitive data.

Generated by OpenCVE AI on August 12, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.7.4 or later, which contains the proper filtering fix for renderAttributeView.
  • Restrict or disable anonymous read access to databases, limiting exposure of sensitive information to authenticated users only.
  • Review database configurations to ensure that published databases do not reference hidden or password‑protected databases and remove any unintended relationship links.

Generated by OpenCVE AI on August 12, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type.
Title SiYuan before v3.7.4 Information Disclosure via renderAttributeView
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-12T19:34:45.544Z

Reserved: 2026-08-10T15:11:03.190Z

Link: CVE-2026-72798

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:51.543

Modified: 2026-08-12T20:17:51.543

Link: CVE-2026-72798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:15:03Z

Weaknesses