← Voltar à pesquisa de CVEs

CVE-2026-73607

SiYuan

Descrição

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading identifiers for any document by supplying its identifier, even for documents forbidden to the requester.

CVSS 5.8EPSS 0.194%Risco 0.59
Ver fonte
Publicação
2026-08-13 12:17:25
Versões afetadas
<3.7.4
Tipo
Aplicação web
Última alteração
2026-08-26 16:57:52
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N