CVE-2026-72788: SiYuan: unauth info leak exposes admin workspace via getConf

GHSA-hgfg-j9pg-43xw MEDIUM PoC AVAILABLE CISA: TRACK*
Published August 12, 2026
CISO Take

SiYuan, a self-hosted knowledge base tool used by some teams to organize AI research, prompts, and internal documentation, ships a publish/sharing mode that fails to isolate administrator workspace state from anonymous readers — anyone who can reach the getConf endpoint can pull the admin's open documents, search terms, notebook directory structure, and private asset paths without logging in. The CVSS 5.8 (confidentiality-only, no integrity or availability impact) and a low EPSS score (0.29%, 78th percentile) mean this isn't the kind of bug that gets mass-exploited overnight, and there's no public PoC, no Nuclei template, and it isn't in CISA KEV — CISA's own SSVC call is TRACK_STAR, i.e. monitor rather than drop everything. That said, the attack requires zero privileges and zero user interaction, so any organization running SiYuan in publish mode with a public-facing instance is trivially exposed to reconnaissance that can reveal where sensitive assets and internal notes live. Upgrade to v3.7.4 or later immediately; until then, disable publish/sharing on any internet-facing SiYuan instance or place it behind an authenticated reverse proxy, and audit access logs for unauthenticated calls to getConf-style endpoints.

Sources: NVD GitHub Advisory EPSS ATLAS www.vulncheck.com

What is the risk?

Medium severity, low-effort exploitation: unauthenticated, network-reachable, no user interaction required (CVSS 5.8, AC:L/PR:N/UI:N). Impact is confined to confidentiality (workspace metadata, not file contents or code execution), which caps the CVSS ceiling. Exploitation likelihood is currently low — EPSS sits at 0.29% (78th percentile), there is no public exploit code, no scanner/Nuclei template, and CISA's SSVC decision is TRACK_STAR (track, don't prioritize urgently). The real risk driver is exposure, not sophistication: any organization that has enabled SiYuan's publish/sharing feature on an internet-facing instance is exposed with essentially no barrier to entry.

How does the attack unfold?

Recon / Initial Access
Attacker identifies a SiYuan instance running in publish/sharing mode that is reachable over the internet.
AML.T0006
Exploitation
Attacker calls the unauthenticated getConf endpoint, bypassing the UILayout filter's intended access restriction (CWE-863).
AML.T0049
Information Disclosure
Response leaks the admin's open documents, search terms, notebook paths, and private asset locations without any credentials.
AML.T0036
Impact
Attacker uses the leaked workspace map to identify sensitive notes or plan targeted follow-up attacks (e.g., social engineering, further path probing).
AML.T0087

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260812083335-251596fc0de2 0.0.0-20260812083335-251596fc0de2
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
5.8 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 33% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C Low
I None
A None

What should I do?

1 step
  1. Upgrade all SiYuan instances to v3.7.4 or later immediately. Until patched, disable the publish/sharing feature on any internet-facing SiYuan deployment, or place it behind authentication (VPN, reverse-proxy auth, IP allowlist) so getConf and related endpoints are never reachable unauthenticated. Audit whether any SiYuan instance is currently running in publish mode and reachable from the internet. Review access logs for anomalous unauthenticated requests to getConf or other UILayout-filtered API paths as a detection signal. After patching, confirm the fix by verifying getConf no longer returns admin-scoped state to unauthenticated publish readers.

What does CISA's SSVC say?

Decision Track*
Exploitation poc
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.6.2.2 - Information security for AI systems
NIST AI RMF
MANAGE-4.1 - Risks and benefits from third-party AI resources are regularly monitored

Frequently Asked Questions

What is CVE-2026-72788?

SiYuan, a self-hosted knowledge base tool used by some teams to organize AI research, prompts, and internal documentation, ships a publish/sharing mode that fails to isolate administrator workspace state from anonymous readers — anyone who can reach the getConf endpoint can pull the admin's open documents, search terms, notebook directory structure, and private asset paths without logging in. The CVSS 5.8 (confidentiality-only, no integrity or availability impact) and a low EPSS score (0.29%, 78th percentile) mean this isn't the kind of bug that gets mass-exploited overnight, and there's no public PoC, no Nuclei template, and it isn't in CISA KEV — CISA's own SSVC call is TRACK_STAR, i.e. monitor rather than drop everything. That said, the attack requires zero privileges and zero user interaction, so any organization running SiYuan in publish mode with a public-facing instance is trivially exposed to reconnaissance that can reveal where sensitive assets and internal notes live. Upgrade to v3.7.4 or later immediately; until then, disable publish/sharing on any internet-facing SiYuan instance or place it behind an authenticated reverse proxy, and audit access logs for unauthenticated calls to getConf-style endpoints.

Is CVE-2026-72788 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72788, increasing the risk of exploitation.

How to fix CVE-2026-72788?

Upgrade all SiYuan instances to v3.7.4 or later immediately. Until patched, disable the publish/sharing feature on any internet-facing SiYuan deployment, or place it behind authentication (VPN, reverse-proxy auth, IP allowlist) so getConf and related endpoints are never reachable unauthenticated. Audit whether any SiYuan instance is currently running in publish mode and reachable from the internet. Review access logs for anomalous unauthenticated requests to getConf or other UILayout-filtered API paths as a detection signal. After patching, confirm the fix by verifying getConf no longer returns admin-scoped state to unauthenticated publish readers.

What systems are affected by CVE-2026-72788?

This vulnerability affects the following AI/ML architecture patterns: AI knowledge management / notebook tooling, RAG pipelines.

What is the CVSS score for CVE-2026-72788?

CVE-2026-72788 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.41%.

What is the AI security impact?

Affected AI Architectures

AI knowledge management / notebook toolingRAG pipelines

MITRE ATLAS Techniques

AML.T0007 Discover AI Artifacts
AML.T0036 Data from Information Repositories

Compliance Controls Affected

ISO 42001: A.6.2.2
NIST AI RMF: MANAGE-4.1

What are the technical details?

Original Advisory

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication.

Exploitation Scenario

A team runs SiYuan in publish mode to share a subset of documentation publicly (e.g., a public wiki or changelog). An attacker scanning for exposed SiYuan instances identifies the public endpoint, then calls the getConf API without any credentials. The response leaks the admin's currently open documents, recent search queries, the full notebook directory tree, and private asset file paths. The attacker uses this metadata to infer where sensitive material lives (e.g., notebooks named for AI vendor contracts, prompt libraries, or security incident notes), then either requests those specific paths directly if additional endpoints are similarly under-scoped, or uses the information for targeted social engineering against the admin.

Weaknesses (CWE)

CWE-863 — Incorrect Authorization: The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
October 1, 2026
First Seen
August 12, 2026

Related Vulnerabilities