CVE-2026-72790: SiYuan: missing authz leaks notebook metadata

GHSA-74pj-6g7r-j55c MEDIUM PoC AVAILABLE
Published August 12, 2026
CISO Take

SiYuan before v3.7.4 exposes the /api/notebook/getNotebookInfo endpoint without an authorization check, letting any network-adjacent caller enumerate notebook names, document counts, sizes, and timestamps for notebooks that are supposed to be closed or unpublished. There's no authentication or user interaction required, so exploitation is trivial for anyone who can reach the API, but the impact is limited to metadata disclosure — no document content, credentials, or write access is exposed, which is why CVSS lands at only 5.8 (confidentiality-low, no integrity or availability impact). EPSS sits at 0.24%, there's no CISA KEV listing, no public exploit or Nuclei template, and CISA's SSVC decision is TRACK — meaning this is a low-urgency background risk rather than an active threat. For teams running self-hosted SiYuan as a personal or team knowledge base (including as a document source feeding AI workflows), the practical action is to upgrade to v3.7.4+, ensure the SiYuan API/UI is not exposed directly to untrusted networks, and audit access logs for unexpected calls to getNotebookInfo if the instance has ever been internet-facing.

Sources: NVD GitHub Advisory EPSS CISA KEV ATLAS

What is the risk?

Medium severity, low urgency. The vulnerability requires no authentication or user interaction and is trivially exploitable over the network (AC:L, PR:N, UI:N), but the impact is confined to metadata disclosure (notebook names, doc counts, sizes, timestamps) with no confidentiality of document content, no integrity, and no availability impact. Absence from CISA KEV, absence of public exploit code or scanner templates, a very low EPSS score (0.24%), and a CISA SSVC verdict of TRACK all indicate this is not being actively exploited and is unlikely to be prioritized by opportunistic attackers. The main real-world risk is reconnaissance value: metadata enumeration can help an attacker map which notebooks exist and are worth targeting for further attacks (e.g., social engineering, targeted exploitation of other SiYuan flaws, or informing which internal knowledge bases to pursue).

How does the attack unfold?

Reconnaissance
Attacker identifies a network-reachable SiYuan instance (internet-facing or on an accessible internal segment).
AML.T0006
Exploitation
Attacker sends an unauthenticated request to /api/notebook/getNotebookInfo to bypass the missing authorization check.
Impact
Attacker obtains metadata (names, document counts, sizes, timestamps) for closed/unpublished notebooks, enabling reconnaissance for further targeting.
AML.T0036

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260726005141-9edb321eb451 0.0.0-20260726005141-9edb321eb451
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
5.8 / 10
EPSS
0.3%
chance of exploitation in 30 days
Higher than 23% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C Low
I None
A None

What should I do?

1 step
  1. 1) Upgrade SiYuan to v3.7.4 or later, which fixes the missing authorization check. 2) Do not expose the SiYuan API/UI directly to the public internet — place it behind a VPN, reverse proxy with authentication, or restrict access via firewall/allowlist to trusted networks only. 3) Review SiYuan's built-in access-control/API-token settings and ensure they are enabled and enforced for all notebook operations, not just document reads. 4) For detection, audit any exposed instance's HTTP access logs for repeated or anomalous calls to /api/notebook/getNotebookInfo from unauthenticated or unexpected source IPs. 5) Treat notebook names as potentially sensitive and avoid embedding client/project identifiers directly in notebook titles on instances that may ever be network-exposed.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Auth Bypass Data Leakage API RAG AML.T0036

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.6.2.6 - AI system security controls / access control

Frequently Asked Questions

What is CVE-2026-72790?

SiYuan before v3.7.4 exposes the /api/notebook/getNotebookInfo endpoint without an authorization check, letting any network-adjacent caller enumerate notebook names, document counts, sizes, and timestamps for notebooks that are supposed to be closed or unpublished. There's no authentication or user interaction required, so exploitation is trivial for anyone who can reach the API, but the impact is limited to metadata disclosure — no document content, credentials, or write access is exposed, which is why CVSS lands at only 5.8 (confidentiality-low, no integrity or availability impact). EPSS sits at 0.24%, there's no CISA KEV listing, no public exploit or Nuclei template, and CISA's SSVC decision is TRACK — meaning this is a low-urgency background risk rather than an active threat. For teams running self-hosted SiYuan as a personal or team knowledge base (including as a document source feeding AI workflows), the practical action is to upgrade to v3.7.4+, ensure the SiYuan API/UI is not exposed directly to untrusted networks, and audit access logs for unexpected calls to getNotebookInfo if the instance has ever been internet-facing.

Is CVE-2026-72790 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72790, increasing the risk of exploitation.

How to fix CVE-2026-72790?

1) Upgrade SiYuan to v3.7.4 or later, which fixes the missing authorization check. 2) Do not expose the SiYuan API/UI directly to the public internet — place it behind a VPN, reverse proxy with authentication, or restrict access via firewall/allowlist to trusted networks only. 3) Review SiYuan's built-in access-control/API-token settings and ensure they are enabled and enforced for all notebook operations, not just document reads. 4) For detection, audit any exposed instance's HTTP access logs for repeated or anomalous calls to /api/notebook/getNotebookInfo from unauthenticated or unexpected source IPs. 5) Treat notebook names as potentially sensitive and avoid embedding client/project identifiers directly in notebook titles on instances that may ever be network-exposed.

What systems are affected by CVE-2026-72790?

This vulnerability affects the following AI/ML architecture patterns: Self-hosted knowledge management / note-taking backends, RAG pipelines (when SiYuan is used as a document source for retrieval context).

What is the CVSS score for CVE-2026-72790?

CVE-2026-72790 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.33%.

What is the AI security impact?

Affected AI Architectures

Self-hosted knowledge management / note-taking backendsRAG pipelines (when SiYuan is used as a document source for retrieval context)

MITRE ATLAS Techniques

AML.T0036 Data from Information Repositories

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.6

What are the technical details?

Original Advisory

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.

Exploitation Scenario

An attacker discovers a SiYuan instance exposed on the internet or an internal network segment they have access to (e.g., via port/service scanning). Without needing any credentials, they send a request to /api/notebook/getNotebookInfo and receive metadata for notebooks that the operator believed were hidden — including closed or unpublished notebooks not meant to be visible to readers. Using the notebook names, sizes, and document counts, the attacker builds a map of what knowledge exists on the instance, prioritizing which notebooks look most valuable (e.g., ones named after clients, projects, or credentials-adjacent topics) for follow-on attacks such as targeted phishing, credential-stuffing against the SiYuan login, or chaining with a separate vulnerability to access document content.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 8, 2026
First Seen
August 12, 2026

Related Vulnerabilities