CVE-2026-72790: SiYuan: missing authz leaks notebook metadata
GHSA-74pj-6g7r-j55c MEDIUM PoC AVAILABLESiYuan before v3.7.4 exposes the /api/notebook/getNotebookInfo endpoint without an authorization check, letting any network-adjacent caller enumerate notebook names, document counts, sizes, and timestamps for notebooks that are supposed to be closed or unpublished. There's no authentication or user interaction required, so exploitation is trivial for anyone who can reach the API, but the impact is limited to metadata disclosure — no document content, credentials, or write access is exposed, which is why CVSS lands at only 5.8 (confidentiality-low, no integrity or availability impact). EPSS sits at 0.24%, there's no CISA KEV listing, no public exploit or Nuclei template, and CISA's SSVC decision is TRACK — meaning this is a low-urgency background risk rather than an active threat. For teams running self-hosted SiYuan as a personal or team knowledge base (including as a document source feeding AI workflows), the practical action is to upgrade to v3.7.4+, ensure the SiYuan API/UI is not exposed directly to untrusted networks, and audit access logs for unexpected calls to getNotebookInfo if the instance has ever been internet-facing.
What is the risk?
Medium severity, low urgency. The vulnerability requires no authentication or user interaction and is trivially exploitable over the network (AC:L, PR:N, UI:N), but the impact is confined to metadata disclosure (notebook names, doc counts, sizes, timestamps) with no confidentiality of document content, no integrity, and no availability impact. Absence from CISA KEV, absence of public exploit code or scanner templates, a very low EPSS score (0.24%), and a CISA SSVC verdict of TRACK all indicate this is not being actively exploited and is unlikely to be prioritized by opportunistic attackers. The main real-world risk is reconnaissance value: metadata enumeration can help an attacker map which notebooks exist and are worth targeting for further attacks (e.g., social engineering, targeted exploitation of other SiYuan flaws, or informing which internal knowledge bases to pursue).
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260726005141-9edb321eb451 | 0.0.0-20260726005141-9edb321eb451 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
1) Upgrade SiYuan to v3.7.4 or later, which fixes the missing authorization check. 2) Do not expose the SiYuan API/UI directly to the public internet — place it behind a VPN, reverse proxy with authentication, or restrict access via firewall/allowlist to trusted networks only. 3) Review SiYuan's built-in access-control/API-token settings and ensure they are enabled and enforced for all notebook operations, not just document reads. 4) For detection, audit any exposed instance's HTTP access logs for repeated or anomalous calls to /api/notebook/getNotebookInfo from unauthenticated or unexpected source IPs. 5) Treat notebook names as potentially sensitive and avoid embedding client/project identifiers directly in notebook titles on instances that may ever be network-exposed.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72790?
SiYuan before v3.7.4 exposes the /api/notebook/getNotebookInfo endpoint without an authorization check, letting any network-adjacent caller enumerate notebook names, document counts, sizes, and timestamps for notebooks that are supposed to be closed or unpublished. There's no authentication or user interaction required, so exploitation is trivial for anyone who can reach the API, but the impact is limited to metadata disclosure — no document content, credentials, or write access is exposed, which is why CVSS lands at only 5.8 (confidentiality-low, no integrity or availability impact). EPSS sits at 0.24%, there's no CISA KEV listing, no public exploit or Nuclei template, and CISA's SSVC decision is TRACK — meaning this is a low-urgency background risk rather than an active threat. For teams running self-hosted SiYuan as a personal or team knowledge base (including as a document source feeding AI workflows), the practical action is to upgrade to v3.7.4+, ensure the SiYuan API/UI is not exposed directly to untrusted networks, and audit access logs for unexpected calls to getNotebookInfo if the instance has ever been internet-facing.
Is CVE-2026-72790 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72790, increasing the risk of exploitation.
How to fix CVE-2026-72790?
1) Upgrade SiYuan to v3.7.4 or later, which fixes the missing authorization check. 2) Do not expose the SiYuan API/UI directly to the public internet — place it behind a VPN, reverse proxy with authentication, or restrict access via firewall/allowlist to trusted networks only. 3) Review SiYuan's built-in access-control/API-token settings and ensure they are enabled and enforced for all notebook operations, not just document reads. 4) For detection, audit any exposed instance's HTTP access logs for repeated or anomalous calls to /api/notebook/getNotebookInfo from unauthenticated or unexpected source IPs. 5) Treat notebook names as potentially sensitive and avoid embedding client/project identifiers directly in notebook titles on instances that may ever be network-exposed.
What systems are affected by CVE-2026-72790?
This vulnerability affects the following AI/ML architecture patterns: Self-hosted knowledge management / note-taking backends, RAG pipelines (when SiYuan is used as a document source for retrieval context).
What is the CVSS score for CVE-2026-72790?
CVE-2026-72790 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.33%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0036 Data from Information Repositories Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.
Exploitation Scenario
An attacker discovers a SiYuan instance exposed on the internet or an internal network segment they have access to (e.g., via port/service scanning). Without needing any credentials, they send a request to /api/notebook/getNotebookInfo and receive metadata for notebooks that the operator believed were hidden — including closed or unpublished notebooks not meant to be visible to readers. Using the notebook names, sizes, and document counts, the attacker builds a map of what knowledge exists on the instance, prioritizing which notebooks look most valuable (e.g., ones named after clients, projects, or credentials-adjacent topics) for follow-on attacks such as targeted phishing, credential-stuffing against the SiYuan login, or chaining with a separate vulnerability to access document content.
Weaknesses (CWE)
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization
Primary
CWE-862 Missing Authorization CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-74pj-6g7r-j55c
- vulncheck.com/advisories/siyuan-before-information-disclosure-via-getnotebookinfo
- github.com/advisories/GHSA-74pj-6g7r-j55c
- github.com/siyuan-note/siyuan/commit/9edb321eb451db445f3c824380e1993c3df0fc16
- nvd.nist.gov/vuln/detail/CVE-2026-72790
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook