Missing Authorization in SiYuan Development Endpoint

⚠️ CVE-Referenzen: CVE-2026-73608
Siyuan-note - Siyuan - CRITICAL - CVE-2026-73608. SiYuan's development branch contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. This issue allows unauthenticated users to access sensitive data by exploiting the endpoint, which does not enforce proper authorization controls. By providing a database identifier from a public page and a relevant keyword, attackers can retrieve data that is normally restricted by the application's access controls, compromising the confidentiality of the data. The vulnerability has been patched in version 3.7.4.
Quelle: securityvulnerability.io