CVE-2026-72788: SiYuan: unauth info leak exposes admin workspace via getConf
GHSA-hgfg-j9pg-43xw MEDIUM PoC AVAILABLE CISA: TRACK*SiYuan, a self-hosted knowledge base tool used by some teams to organize AI research, prompts, and internal documentation, ships a publish/sharing mode that fails to isolate administrator workspace state from anonymous readers — anyone who can reach the getConf endpoint can pull the admin's open documents, search terms, notebook directory structure, and private asset paths without logging in. The CVSS 5.8 (confidentiality-only, no integrity or availability impact) and a low EPSS score (0.29%, 78th percentile) mean this isn't the kind of bug that gets mass-exploited overnight, and there's no public PoC, no Nuclei template, and it isn't in CISA KEV — CISA's own SSVC call is TRACK_STAR, i.e. monitor rather than drop everything. That said, the attack requires zero privileges and zero user interaction, so any organization running SiYuan in publish mode with a public-facing instance is trivially exposed to reconnaissance that can reveal where sensitive assets and internal notes live. Upgrade to v3.7.4 or later immediately; until then, disable publish/sharing on any internet-facing SiYuan instance or place it behind an authenticated reverse proxy, and audit access logs for unauthenticated calls to getConf-style endpoints.
What is the risk?
Medium severity, low-effort exploitation: unauthenticated, network-reachable, no user interaction required (CVSS 5.8, AC:L/PR:N/UI:N). Impact is confined to confidentiality (workspace metadata, not file contents or code execution), which caps the CVSS ceiling. Exploitation likelihood is currently low — EPSS sits at 0.29% (78th percentile), there is no public exploit code, no scanner/Nuclei template, and CISA's SSVC decision is TRACK_STAR (track, don't prioritize urgently). The real risk driver is exposure, not sophistication: any organization that has enabled SiYuan's publish/sharing feature on an internet-facing instance is exposed with essentially no barrier to entry.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260812083335-251596fc0de2 | 0.0.0-20260812083335-251596fc0de2 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade all SiYuan instances to v3.7.4 or later immediately. Until patched, disable the publish/sharing feature on any internet-facing SiYuan deployment, or place it behind authentication (VPN, reverse-proxy auth, IP allowlist) so getConf and related endpoints are never reachable unauthenticated. Audit whether any SiYuan instance is currently running in publish mode and reachable from the internet. Review access logs for anomalous unauthenticated requests to getConf or other UILayout-filtered API paths as a detection signal. After patching, confirm the fix by verifying getConf no longer returns admin-scoped state to unauthenticated publish readers.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72788?
SiYuan, a self-hosted knowledge base tool used by some teams to organize AI research, prompts, and internal documentation, ships a publish/sharing mode that fails to isolate administrator workspace state from anonymous readers — anyone who can reach the getConf endpoint can pull the admin's open documents, search terms, notebook directory structure, and private asset paths without logging in. The CVSS 5.8 (confidentiality-only, no integrity or availability impact) and a low EPSS score (0.29%, 78th percentile) mean this isn't the kind of bug that gets mass-exploited overnight, and there's no public PoC, no Nuclei template, and it isn't in CISA KEV — CISA's own SSVC call is TRACK_STAR, i.e. monitor rather than drop everything. That said, the attack requires zero privileges and zero user interaction, so any organization running SiYuan in publish mode with a public-facing instance is trivially exposed to reconnaissance that can reveal where sensitive assets and internal notes live. Upgrade to v3.7.4 or later immediately; until then, disable publish/sharing on any internet-facing SiYuan instance or place it behind an authenticated reverse proxy, and audit access logs for unauthenticated calls to getConf-style endpoints.
Is CVE-2026-72788 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72788, increasing the risk of exploitation.
How to fix CVE-2026-72788?
Upgrade all SiYuan instances to v3.7.4 or later immediately. Until patched, disable the publish/sharing feature on any internet-facing SiYuan deployment, or place it behind authentication (VPN, reverse-proxy auth, IP allowlist) so getConf and related endpoints are never reachable unauthenticated. Audit whether any SiYuan instance is currently running in publish mode and reachable from the internet. Review access logs for anomalous unauthenticated requests to getConf or other UILayout-filtered API paths as a detection signal. After patching, confirm the fix by verifying getConf no longer returns admin-scoped state to unauthenticated publish readers.
What systems are affected by CVE-2026-72788?
This vulnerability affects the following AI/ML architecture patterns: AI knowledge management / notebook tooling, RAG pipelines.
What is the CVSS score for CVE-2026-72788?
CVE-2026-72788 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.41%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0007 Discover AI Artifacts AML.T0036 Data from Information Repositories Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication.
Exploitation Scenario
A team runs SiYuan in publish mode to share a subset of documentation publicly (e.g., a public wiki or changelog). An attacker scanning for exposed SiYuan instances identifies the public endpoint, then calls the getConf API without any credentials. The response leaks the admin's currently open documents, recent search queries, the full notebook directory tree, and private asset file paths. The attacker uses this metadata to infer where sensitive material lives (e.g., notebooks named for AI vendor contracts, prompt libraries, or security incident notes), then either requests those specific paths directly if additional endpoints are similarly under-scoped, or uses the information for targeted social engineering against the admin.
Weaknesses (CWE)
CWE-863 Incorrect Authorization
Primary
CWE-863 Incorrect Authorization
Primary
CWE-863 Incorrect Authorization CWE-863 — Incorrect Authorization: The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N References
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook