Junglewise Threat Intelligence

CVE-2026-73609: SiYuan getBookmarkLabels information disclosure

CVE-2026-73609 · Severity: medium · CVSS 5.8 · Published 2026-08-13

Technologies: SiYuan Note SiYuan. Vendors: SiYuan Note.

Executive brief

SiYuan is a popular note-taking and knowledge-management application. The getBookmarkLabels API endpoint fails to filter bookmark labels by access permissions, allowing anonymous and read-only users to obtain a complete list of all bookmark labels across the entire workspace. This leaks information about document contents and organizational structure that the user should not have access to, including details from password-protected, hidden, or restricted documents.

Technical details

The vulnerability is a missing authorization / access control flaw in the /api/attr/getBookmarkLabels endpoint. The handler is registered with CheckAuth only and applies no filtering based on publish-access permissions. It performs an unrestricted query of the entire blocks table and returns all distinct bookmark labels in the workspace. In contrast, the sibling getBookmark endpoint correctly filters results using FilterBlocksByPublishAccess and omits labels entirely when no accessible block carries them. The vulnerable endpoint is reachable by anonymous users in publish mode (when Publish.Auth.Enable is false) and by any publish RoleReader token. The fix is to apply the same access-filtering logic as the getBookmark endpoint, ensuring labels are only returned for blocks the caller has permission to access.

Affected products

  • SiYuan Note SiYuan before v3.7.4

Timeline

  • 2026-07-29: disclosed: GitHub Security Advisory GHSA-j4ph-9xwf-wcj4 published
  • 2026-08-13: patched: Fix released in v3.7.4
  • 2026-08-13: advisory: CVE-2026-73609 assigned

References