CVE-2026-72789: SiYuan: broken access control leaks encrypted notes
GHSA-v684-q882-jgmq HIGH PoC AVAILABLE CISA: TRACK*SiYuan's publish feature fails to enforce access control on notebooks flagged as encrypted, treating them as publicly reachable by default so any anonymous requester can enumerate and pull fully decrypted document content through the publish API without credentials or key material. This is a network-exploitable, zero-interaction flaw (CVSS 8.6, AV:N/AC:L/PR:N/UI:N) with high confidentiality impact and no integrity or availability effect, meaning organizations using SiYuan's sharing feature to host internal research, documentation, or project notes risk silent, undetected disclosure of anything they believed was encrypted. Exploitation likelihood is currently modest: EPSS is only 0.29% (though that ranks in the top 78th percentile relative to other CVEs), the flaw is not in CISA KEV, no public exploit code or Nuclei scanning template exists yet, and CISA's SSVC decision is TRACK_STAR — track it, but it is not an active-exploitation emergency today. Upgrade to SiYuan v3.7.4 or later immediately; until patched, disable or restrict the publish/sharing feature on any encrypted notebook, treat previously published notebooks as potentially exposed, and rotate any credentials or sensitive data they contained.
What is the risk?
High severity by CVSS (8.6) driven by unauthenticated, zero-complexity confidentiality loss of an entire encrypted notebook's contents — the scope change (S:C) reflects that the publish subsystem's failure exposes data beyond its own security boundary. However, real-world exploitation likelihood is currently low-to-moderate: EPSS is 0.29%, there is no CISA KEV listing, no known public exploit or Nuclei template, and SSVC scores it TRACK_STAR (monitor, not urgent action). Net risk is elevated primarily by the low bar to exploit (no auth, no interaction, trivial enumeration) rather than by evidence of active targeting — organizations that use the publish feature on sensitive notebooks should treat this as urgent-to-patch despite the low EPSS.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260726020813-a25c2dd06aae | 0.0.0-20260726020813-a25c2dd06aae |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
1) Upgrade SiYuan to v3.7.4 or later immediately. 2) Until patched, disable the publish/sharing feature entirely, or explicitly review and lock down which notebooks are published — do not rely on 'encrypted' status alone to restrict access. 3) Audit publish API logs for anonymous access to notebook content prior to patching to determine if exposure already occurred. 4) Treat any notebook that was ever published as potentially fully disclosed and rotate any embedded credentials, API keys, or sensitive data. 5) For detection, monitor for unauthenticated requests to SiYuan's publish API endpoints from unexpected source IPs.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72789?
SiYuan's publish feature fails to enforce access control on notebooks flagged as encrypted, treating them as publicly reachable by default so any anonymous requester can enumerate and pull fully decrypted document content through the publish API without credentials or key material. This is a network-exploitable, zero-interaction flaw (CVSS 8.6, AV:N/AC:L/PR:N/UI:N) with high confidentiality impact and no integrity or availability effect, meaning organizations using SiYuan's sharing feature to host internal research, documentation, or project notes risk silent, undetected disclosure of anything they believed was encrypted. Exploitation likelihood is currently modest: EPSS is only 0.29% (though that ranks in the top 78th percentile relative to other CVEs), the flaw is not in CISA KEV, no public exploit code or Nuclei scanning template exists yet, and CISA's SSVC decision is TRACK_STAR — track it, but it is not an active-exploitation emergency today. Upgrade to SiYuan v3.7.4 or later immediately; until patched, disable or restrict the publish/sharing feature on any encrypted notebook, treat previously published notebooks as potentially exposed, and rotate any credentials or sensitive data they contained.
Is CVE-2026-72789 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72789, increasing the risk of exploitation.
How to fix CVE-2026-72789?
1) Upgrade SiYuan to v3.7.4 or later immediately. 2) Until patched, disable the publish/sharing feature entirely, or explicitly review and lock down which notebooks are published — do not rely on 'encrypted' status alone to restrict access. 3) Audit publish API logs for anonymous access to notebook content prior to patching to determine if exposure already occurred. 4) Treat any notebook that was ever published as potentially fully disclosed and rotate any embedded credentials, API keys, or sensitive data. 5) For detection, monitor for unauthenticated requests to SiYuan's publish API endpoints from unexpected source IPs.
What systems are affected by CVE-2026-72789?
This vulnerability affects the following AI/ML architecture patterns: knowledge management systems, RAG pipelines.
What is the CVSS score for CVE-2026-72789?
CVE-2026-72789 has a CVSS v3.1 base score of 8.6 (HIGH). The EPSS exploitation probability is 0.50%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0025 Exfiltration via Cyber Means AML.T0036 Data from Information Repositories Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
Exploitation Scenario
An adversary discovers a self-hosted or cloud-exposed SiYuan instance via search engines, Shodan, or targeted reconnaissance of a victim organization's infrastructure. They probe the publish API and find that encrypted notebooks are still enumerable and retrievable without authentication. The adversary requests the publish endpoints for each discovered notebook ID and receives fully decrypted document content — potentially internal research notes, project documentation, or AI system design notes — with no login, API key, or decryption key required, exfiltrating the data directly over the network.
Weaknesses (CWE)
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-v684-q882-jgmq
- vulncheck.com/advisories/siyuan-before-authentication-bypass-via-encrypted-notebooks
- github.com/advisories/GHSA-v684-q882-jgmq
- github.com/siyuan-note/siyuan/commit/a25c2dd06aae13d1de70cc61cbf98169689c9d86
- nvd.nist.gov/vuln/detail/CVE-2026-72789
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook