Executive brief
SiYuan is an open-source note-taking and knowledge-management application that supports publishing pages for public viewing. The vulnerability allows anonymous readers to bypass access controls and retrieve database row content that should be restricted, including sensitive data from published pages that applies visibility filters. An attacker can systematically extract private database records by querying published databases without proper authorization checks.
Technical details
The /api/av/getAttributeViewSearchTarget endpoint in SiYuan's development branch (introduced by commit 9b8e8956f, patched in v3.7.4) lacks authorization checks, registering only CheckAuth without CheckReadonly, publish-access filtering, or encrypted-notebook gating. The vulnerability allows an anonymous user to provide a database identifier obtained from published page DOM and search keywords to retrieve matching database rows, bypassing the per-item filtering (FilterAttributeViewByPublishAccess) that the adjacent renderAttributeView endpoint applies. The response includes MatchedKeyID, enabling substring searching without retrieving data wholesale. Attack preconditions: publish mode enabled, database block ID visible in published page DOM. No released stable version (v3.7.3 or master) is affected; the endpoint exists only on the development branch prior to the v3.7.4 patch.
Affected products
- SiYuan SiYuan development branch (introduced by commit 9b8e8956f); not present in v3.7.3 or master; patched in v3.7.4
Timeline
- 2026-08-13: disclosed: NVD published CVE-2026-73608
- 2026-07-29: patched: Patched in v3.7.4 (private report, prior to public disclosure)
- 2026-07-27: other: Endpoint introduced by commit 9b8e8956f on development branch
- 2026-07-26: other: Related authorization fix (commit 64c26e74b) applied to getAttributeViewFieldViews endpoint one day before vulnerable endpoint was added