CVE-2026-72789: SiYuan: broken access control leaks encrypted notes

GHSA-v684-q882-jgmq HIGH PoC AVAILABLE CISA: TRACK*
Published August 12, 2026
CISO Take

SiYuan's publish feature fails to enforce access control on notebooks flagged as encrypted, treating them as publicly reachable by default so any anonymous requester can enumerate and pull fully decrypted document content through the publish API without credentials or key material. This is a network-exploitable, zero-interaction flaw (CVSS 8.6, AV:N/AC:L/PR:N/UI:N) with high confidentiality impact and no integrity or availability effect, meaning organizations using SiYuan's sharing feature to host internal research, documentation, or project notes risk silent, undetected disclosure of anything they believed was encrypted. Exploitation likelihood is currently modest: EPSS is only 0.29% (though that ranks in the top 78th percentile relative to other CVEs), the flaw is not in CISA KEV, no public exploit code or Nuclei scanning template exists yet, and CISA's SSVC decision is TRACK_STAR — track it, but it is not an active-exploitation emergency today. Upgrade to SiYuan v3.7.4 or later immediately; until patched, disable or restrict the publish/sharing feature on any encrypted notebook, treat previously published notebooks as potentially exposed, and rotate any credentials or sensitive data they contained.

Sources: NVD GitHub Advisory EPSS vulncheck.com ATLAS

What is the risk?

High severity by CVSS (8.6) driven by unauthenticated, zero-complexity confidentiality loss of an entire encrypted notebook's contents — the scope change (S:C) reflects that the publish subsystem's failure exposes data beyond its own security boundary. However, real-world exploitation likelihood is currently low-to-moderate: EPSS is 0.29%, there is no CISA KEV listing, no known public exploit or Nuclei template, and SSVC scores it TRACK_STAR (monitor, not urgent action). Net risk is elevated primarily by the low bar to exploit (no auth, no interaction, trivial enumeration) rather than by evidence of active targeting — organizations that use the publish feature on sensitive notebooks should treat this as urgent-to-patch despite the low EPSS.

How does the attack unfold?

Reconnaissance
Adversary identifies a publicly reachable SiYuan instance with the publish feature enabled.
AML.T0006
Exploitation
Adversary sends unauthenticated requests to the publish API and enumerates notebook IDs, bypassing the intended access restriction on encrypted notebooks.
AML.T0049
Collection
Adversary retrieves fully decrypted document content from the encrypted notebooks without any key material.
AML.T0036
Impact
Sensitive notes, documentation, or embedded credentials are exfiltrated and exposed outside the organization's control.
AML.T0025

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260726020813-a25c2dd06aae 0.0.0-20260726020813-a25c2dd06aae
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
8.6 / 10
EPSS
0.5%
chance of exploitation in 30 days
Higher than 41% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C High
I None
A None

What should I do?

1 step
  1. 1) Upgrade SiYuan to v3.7.4 or later immediately. 2) Until patched, disable the publish/sharing feature entirely, or explicitly review and lock down which notebooks are published — do not rely on 'encrypted' status alone to restrict access. 3) Audit publish API logs for anonymous access to notebook content prior to patching to determine if exposure already occurred. 4) Treat any notebook that was ever published as potentially fully disclosed and rotate any embedded credentials, API keys, or sensitive data. 5) For detection, monitor for unauthenticated requests to SiYuan's publish API endpoints from unexpected source IPs.

What does CISA's SSVC say?

Decision Track*
Exploitation poc
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.6.2.2 - AI system data security
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72789?

SiYuan's publish feature fails to enforce access control on notebooks flagged as encrypted, treating them as publicly reachable by default so any anonymous requester can enumerate and pull fully decrypted document content through the publish API without credentials or key material. This is a network-exploitable, zero-interaction flaw (CVSS 8.6, AV:N/AC:L/PR:N/UI:N) with high confidentiality impact and no integrity or availability effect, meaning organizations using SiYuan's sharing feature to host internal research, documentation, or project notes risk silent, undetected disclosure of anything they believed was encrypted. Exploitation likelihood is currently modest: EPSS is only 0.29% (though that ranks in the top 78th percentile relative to other CVEs), the flaw is not in CISA KEV, no public exploit code or Nuclei scanning template exists yet, and CISA's SSVC decision is TRACK_STAR — track it, but it is not an active-exploitation emergency today. Upgrade to SiYuan v3.7.4 or later immediately; until patched, disable or restrict the publish/sharing feature on any encrypted notebook, treat previously published notebooks as potentially exposed, and rotate any credentials or sensitive data they contained.

Is CVE-2026-72789 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72789, increasing the risk of exploitation.

How to fix CVE-2026-72789?

1) Upgrade SiYuan to v3.7.4 or later immediately. 2) Until patched, disable the publish/sharing feature entirely, or explicitly review and lock down which notebooks are published — do not rely on 'encrypted' status alone to restrict access. 3) Audit publish API logs for anonymous access to notebook content prior to patching to determine if exposure already occurred. 4) Treat any notebook that was ever published as potentially fully disclosed and rotate any embedded credentials, API keys, or sensitive data. 5) For detection, monitor for unauthenticated requests to SiYuan's publish API endpoints from unexpected source IPs.

What systems are affected by CVE-2026-72789?

This vulnerability affects the following AI/ML architecture patterns: knowledge management systems, RAG pipelines.

What is the CVSS score for CVE-2026-72789?

CVE-2026-72789 has a CVSS v3.1 base score of 8.6 (HIGH). The EPSS exploitation probability is 0.50%.

What is the AI security impact?

Affected AI Architectures

knowledge management systemsRAG pipelines

MITRE ATLAS Techniques

AML.T0025 Exfiltration via Cyber Means
AML.T0036 Data from Information Repositories

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.2
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.

Exploitation Scenario

An adversary discovers a self-hosted or cloud-exposed SiYuan instance via search engines, Shodan, or targeted reconnaissance of a victim organization's infrastructure. They probe the publish API and find that encrypted notebooks are still enumerable and retrievable without authentication. The adversary requests the publish endpoints for each discovered notebook ID and receives fully decrypted document content — potentially internal research notes, project documentation, or AI system design notes — with no login, API key, or decryption key required, exfiltrating the data directly over the network.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 8, 2026
First Seen
August 12, 2026

Related Vulnerabilities