Description
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.
Published: 2026-08-13
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan versions prior to 3.7.4 contain a flaw in the /getBookmarkLabels endpoint that returns the full list of bookmark labels in a workspace. The response includes labels from all documents, bypassing the publish‑access filter. Therefore, an attacker, even without additional credentials, can learn the naming convention and organization of bookmarks, which in many cases reveals subject matter and organizational structure of otherwise restricted documents.

Affected Systems

The vulnerable software is SiYuan, the knowledge‑management application, for all releases before 3.7.4. Users of earlier builds should verify their install version and consider upgrading to 3.7.4 or later, which removes the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, but the vulnerability is exploitable by anyone with read access to the workspace, including anonymous or publish‑mode readers, without any authentication or privilege escalation. Because the flaw leaks only metadata and not full document contents, the attack vector is limited to information disclosure; privacy and reputational impacts result from exposing content organization across the workspace. The issue is not listed in the CISA KEV catalog at this time.

Generated by OpenCVE AI on August 13, 2026 at 12:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.7.4 or later to remove the flaw.
  • Restrict publish mode and anonymous read access for workspaces that contain sensitive or restricted documents.
  • Implement or verify access‑control policies to ensure that only authorized users can retrieve bookmark metadata.

Generated by OpenCVE AI on August 13, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Siyuan
Siyuan siyuan
Vendors & Products Siyuan
Siyuan siyuan

Thu, 13 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.
Title SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T11:28:13.793Z

Reserved: 2026-08-13T11:15:12.096Z

Link: CVE-2026-73609

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T12:17:25.463

Modified: 2026-08-13T12:17:25.463

Link: CVE-2026-73609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:20:11Z

Weaknesses