CVE-2026-72797: SiYuan: missing authz leaks encrypted notebook metadata

GHSA-f2rw-w22v-54vh MEDIUM PoC AVAILABLE
Published August 12, 2026
CISO Take

SiYuan before v3.7.4 exposes an unauthenticated endpoint, getEncryptedNotebookStatus, that returns the identifiers, names, and lock/unlock state of encrypted notebooks to anonymous readers and publish-mode accounts, without checking whether the requester actually has publish access. This matters less for raw severity — CVSS 5.8 medium, confidentiality-only impact, EPSS still low, no CISA KEV listing, no public exploit or Nuclei template — and more because it is a zero-effort reconnaissance primitive: no credentials, no user interaction, and it hands an attacker a map of which encrypted notebooks exist, what they're named, and whether they're currently unlocked in memory. For self-hosted SiYuan instances used as personal or team knowledge bases (including AI-assisted note-taking), that metadata is enough to target social engineering or time follow-on attacks against a notebook while it sits unlocked. Upgrade to v3.7.4 or later; until patched, restrict or disable public/publish-mode access to SiYuan instances and audit access logs for repeated calls to the endpoint as an enumeration signal.

Sources: NVD GitHub Advisory EPSS ATLAS VulnCheck

What is the risk?

Medium risk overall: the flaw requires no authentication or user interaction and is trivially scriptable (AV:N/AC:L/PR:N/UI:N), but the CVSS vector caps impact at confidentiality-low with no integrity or availability effect (C:L/I:N/A:N) — only metadata (IDs, names, lock state) is exposed, not notebook contents. EPSS remains low and the CVE is not in CISA KEV, has no public exploit code, and no Nuclei template exists, so mass exploitation is unlikely in the near term. The realistic risk is targeted: an attacker who already has some form of access to a publish-mode SiYuan deployment (a common self-hosted note-taking setup) can use this to fingerprint sensitive notebooks and time follow-on attacks.

How does the attack unfold?

Unauthenticated Access
Attacker reaches a SiYuan instance's publish-mode interface as an anonymous reader or unprivileged publish-mode account.
AML.T0049
Metadata Enumeration
Attacker calls getEncryptedNotebookStatus, which returns encrypted notebook IDs, names, and lock states without checking publish-access rights.
AML.T0036
Targeting
Attacker uses the leaked notebook names and unlock-state timing to craft targeted phishing or to time follow-on attacks against a notebook while it is unlocked in memory.
AML.T0064
Impact
Sensitive knowledge-base structure and state is disclosed, enabling reconnaissance-driven follow-on data exposure even though the raw notebook content itself is not directly returned.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260724123622-8fb1b5766093 0.0.0-20260724123622-8fb1b5766093
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
5.8 / 10
EPSS
0.3%
chance of exploitation in 30 days
Higher than 23% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C Low
I None
A None

What should I do?

1 step
  1. Upgrade SiYuan to v3.7.4 or later, which adds publish-access filtering to getEncryptedNotebookStatus. Until patched: do not expose publish-mode SiYuan instances directly to the internet without a reverse-proxy access control layer (VPN, IP allowlist, or auth gate in front of publish endpoints); disable publish mode for encrypted notebooks if not strictly needed. Detection: monitor web server / reverse proxy logs for repeated unauthenticated calls to getEncryptedNotebookStatus as an enumeration indicator, and review who has publish-mode account access. Reference the vendor advisory (GHSA-f2rw-w22v-54vh) and VulnCheck write-up for patch details.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, Robustness and Cybersecurity
NIST AI RMF
MAP 1.1 / MEASURE 2.7 - AI System Data Governance and Security
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72797?

SiYuan before v3.7.4 exposes an unauthenticated endpoint, getEncryptedNotebookStatus, that returns the identifiers, names, and lock/unlock state of encrypted notebooks to anonymous readers and publish-mode accounts, without checking whether the requester actually has publish access. This matters less for raw severity — CVSS 5.8 medium, confidentiality-only impact, EPSS still low, no CISA KEV listing, no public exploit or Nuclei template — and more because it is a zero-effort reconnaissance primitive: no credentials, no user interaction, and it hands an attacker a map of which encrypted notebooks exist, what they're named, and whether they're currently unlocked in memory. For self-hosted SiYuan instances used as personal or team knowledge bases (including AI-assisted note-taking), that metadata is enough to target social engineering or time follow-on attacks against a notebook while it sits unlocked. Upgrade to v3.7.4 or later; until patched, restrict or disable public/publish-mode access to SiYuan instances and audit access logs for repeated calls to the endpoint as an enumeration signal.

Is CVE-2026-72797 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72797, increasing the risk of exploitation.

How to fix CVE-2026-72797?

Upgrade SiYuan to v3.7.4 or later, which adds publish-access filtering to getEncryptedNotebookStatus. Until patched: do not expose publish-mode SiYuan instances directly to the internet without a reverse-proxy access control layer (VPN, IP allowlist, or auth gate in front of publish endpoints); disable publish mode for encrypted notebooks if not strictly needed. Detection: monitor web server / reverse proxy logs for repeated unauthenticated calls to getEncryptedNotebookStatus as an enumeration indicator, and review who has publish-mode account access. Reference the vendor advisory (GHSA-f2rw-w22v-54vh) and VulnCheck write-up for patch details.

What systems are affected by CVE-2026-72797?

This vulnerability affects the following AI/ML architecture patterns: RAG pipelines, self-hosted knowledge bases.

What is the CVSS score for CVE-2026-72797?

CVE-2026-72797 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.33%.

What is the AI security impact?

Affected AI Architectures

RAG pipelinesself-hosted knowledge bases

MITRE ATLAS Techniques

AML.T0036 Data from Information Repositories
AML.T0064 Gather RAG-Indexed Targets

Compliance Controls Affected

EU AI Act: Article 15
NIST AI RMF: MAP 1.1 / MEASURE 2.7
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can enumerate all encrypted notebooks and their current unlock status, revealing sensitive notebook names and decryption state in memory.

Exploitation Scenario

An attacker locates a publicly reachable SiYuan instance running in publish mode (common for self-hosted note-sharing setups) and, without authenticating, calls getEncryptedNotebookStatus. The response enumerates every encrypted notebook's ID, name, and current lock state. The attacker now knows a notebook named "Client Credentials" exists and is periodically unlocked during business hours. They use the notebook name to craft a convincing phishing email to the notebook owner referencing it by name, or they poll the endpoint to catch the window when the notebook is unlocked in memory and pivot to other endpoints or client-side attacks to attempt to read its contents during that window.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Timeline

Published
August 12, 2026
Last Modified
September 4, 2026
First Seen
August 12, 2026

Related Vulnerabilities