CVE-2026-73048
Received Received - Intake

SiYuan Information Disclosure via PDF Annotation Endpoint

Vulnerability report for CVE-2026-73048, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: VulnCheck

Description

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by supplying annotation identifiers visible in published pages, revealing citation relationships across forbidden and password-protected tiers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-73048 is an information disclosure vulnerability in SiYuan note-taking app versions before v3.7.4. It affects the /api/block/getRefIDsByFileAnnotationID endpoint, which returns block identifiers citing PDF annotations without proper access filtering. Attackers can exploit this by using annotation IDs visible in public documents to extract block IDs from restricted or password-protected documents, revealing citation relationships across unauthorized tiers.

Detection Guidance

Check if your SiYuan instance is running a version before v3.7.4. Inspect network traffic for requests to the /api/block/getRefIDsByFileAnnotationID endpoint. Look for responses containing block identifiers from restricted documents without proper authorization.

Impact Analysis

This vulnerability allows unauthorized users to access block identifiers from restricted documents, potentially revealing sensitive information about document structure or content relationships. While it does not expose the actual content of restricted documents, it could help attackers identify targets or understand document organization without proper access.

Compliance Impact

This vulnerability could impact compliance with data protection regulations like GDPR or HIPAA by potentially exposing metadata about restricted documents. While it does not directly disclose sensitive data, it may reveal information about document relationships or structure that could be considered sensitive under these regulations, depending on organizational policies.

Mitigation Strategies

Upgrade SiYuan to version v3.7.4 or later. Ensure the /api/block/getRefIDsByFileAnnotationID endpoint applies publish-access filtering like other endpoints. Review and restrict access to annotation IDs visible in published pages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73048. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart